VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities
2026-07-09T20:52:10Z•09dbb40894a5b42474747f2d4ed54562e924c89fce428fa272ee2859c1a04e69
API over‑fetchingAdaloAndroidCORSJWT exposureJavaScript injectionPayRangeRCESSL/TLS bypassStripeTendaWebViewXSSXerte Online Toolkitantivirus binary pathauthentication bypassauthorization failurecredential theftdata exposurefirmware backdoorhardware controlno-code platformremote code executionsetup directory persistenceundocumented backdoor authentication
What happened
This document aggregates multiple vulnerability advisories affecting a range of products: PayRange Android app (WebView SSL bypass and JavaScript injection enabling credential theft and hardware control), Xerte Online Toolkit (post-installation setup persistence allowing reconfiguration/auth bypass and an editable antivirus path enabling RCE), Adalo platform (platform-level API over‑fetching and exposed long‑lived JWTs leading to mass user‑data disclosure), multiple Tenda firmware images (undocumented backdoor granting admin access), HP Deskjet 2800 series firmware (missing authorization onAPI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 09dbb40894a5b42474747f2d4ed54562e924c89fce428fa272ee2859c1a04e69
- Enrichment time
- 2026-07-09T20:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.