CVE-2026-4582 Details
Description
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation leads to missing authentication. The attack must be carried out from within the local network. Attacks of this nature are highly complex. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in the Shenzhen HCC Technology MPOS M6 PLUS version 1V.31-N, specifically within the Bluetooth component. This vulnerability arises from a complete lack of cryptographic authentication, allowing any Bluetooth device to inject arbitrary transaction commands. The only integrity check available is a simple single-byte XOR checksum, which can be easily manipulated. Exploitation of this vulnerability requires access to the local network and involves complex attack vectors.
It is recommended to implement HMAC-SHA256 for message authentication, migrate to TLS 1.3 for mutual authentication and encryption, or add device pairing validation, although the latter is weaker than cryptographic authentication.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 23, 2026CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Shenzhen HCC Technology MPOS M6 PLUS | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 18, 2026 | CVE Modified | [email protected] |
| Mar 23, 2026 | New CVE Received | [email protected] |
Volerion