CVE-2025-46018
MEDIUMCSC Pay Mobile App 2.19.4 - Authentication Bypass via Bluetooth Disabling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-46018. PoCs published by niranjangaire1995.
AI-analyzed exploit summary This repository documents an authentication bypass vulnerability (CVE-2025-46018) in the CSC Pay Mobile App version 2.19.4, where disabling Bluetooth during payment allows unauthorized machine activation without charge.
Description
CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss.
Exploits (1)
This repository documents an authentication bypass vulnerability (CVE-2025-46018) in the CSC Pay Mobile App version 2.19.4, where disabling Bluetooth during payment allows unauthorized machine activation without charge.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L