CVE-2025-46018

C

SC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and potential financial loss.

Configurations

Configuration 1 (hide)

cpe:2.3:a:cscsw:pay_mobile:2.19.4:*:*:*:*:*:*:*

History

14 Oct 2025, 13:36

Type Values Removed Values Added
References () https://github.com/niranjangaire1995/CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass - () https://github.com/niranjangaire1995/CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass - Third Party Advisory
References () https://www.cscsw.com/disclosure-process/ - () https://www.cscsw.com/disclosure-process/ - Product
CPE cpe:2.3:a:cscsw:pay_mobile:2.19.4:*:*:*:*:*:*:*
First Time Cscsw pay Mobile
Cscsw

04 Aug 2025, 15:06

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 14:15

Updated : 2025-10-14 13:36


NVD link : CVE-2025-46018

Mitre link : CVE-2025-46018

CVE.ORG link : CVE-2025-46018


JSON object : View

Products Affected
CWE
CWE-290

Authentication Bypass by Spoofing