nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37168 CVE-2020-37168
CRITICAL
Ecommerce Systempay 1.0 Production Key Brute Force
Record summary
CVE-2020-37168 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash comparison to iteratively test key candidates until discovering the correct production key, enabling them to forge valid payment signatures and manipulate transaction amounts.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ecommerce SystempayBrowse Paiement / Ecommerce Systempay | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBEcommerce Systempay 1.0 - Production KEY Brute ForceExploitDB exploitby live3Not analyzed1 file
References
5Official Product Homepageproduct
https://paiement.systempay.fr/doc/fr-FR Product Referenceproduct
https://paiement.systempay.fr/doc/fr-FR/module-de-paiement-gratuit ExploitDB-48017exploit
https://www.exploit-db.com/exploits/48017 VulnCheck Advisory: Ecommerce Systempay 1.0 Production Key Brute ForceThird-party advisory
https://www.vulncheck.com/advisories/ecommerce-systempay-production-key-brute-force