Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23361 | CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss. |
Tue, 14 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cscsw
Cscsw pay Mobile |
|
| CPEs | cpe:2.3:a:cscsw:pay_mobile:2.19.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Cscsw
Cscsw pay Mobile |
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-01T17:55:17.831Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-46018
Updated: 2025-08-01T17:55:12.181Z
Status : Analyzed
Published: 2025-08-01T14:15:35.260
Modified: 2025-10-14T13:36:46.463
Link: CVE-2025-46018
No data.
OpenCVE Enrichment
No data.
EUVD