Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass — Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4" | Kitploit
Tools/GitHubGitHub/niranjangaire1995/cve-2025-46018-csc-pay-mobile-app-payment-authentication-bypass
Authentication & AuthorizationBluetooth SecurityVulnerability AnalysisExploitationPenetration TestingMobile Security
GitHubniranjangaire1995/cve-2025-46018-csc-pay-mobile-app-payment-authentication-bypass

CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4"

View Repository
1 year agoNot yet reviewed

CVE-2025-46018 – CSC Pay Mobile App Payment Authentication Bypass

Summary

A payment authentication bypass vulnerability was discovered in the CSC Pay Mobile App, affecting version 2.19.4. The flaw allowed an attacker to initiate a payment, disable Bluetooth at a specific point in the process, and activate a laundry machine without being charged.

This issue has been responsibly disclosed and is now tracked as CVE-2025-46018.


Affected Product

  • Product: CSC Pay Mobile App
  • Version: 2.19.4 (fixed in version 2.20.0)
  • Component: Bluetooth payment authentication module
  • Vendor: CSC ServiceWorks

Vulnerability Type

  • CWE-284: Improper Access Control
  • CVSS (estimated): Medium severity
  • Exploit type: Local – requires proximity to the machine

Attack Vector (High-Level)

  1. The attacker initiates a payment via the mobile app and scans the QR code on a laundry machine.
  2. Before the app completes Bluetooth authentication and charges the user, Bluetooth is intentionally disabled.
  3. The machine starts the cycle despite no transaction being completed.

Impact: Unauthorized use of machines without payment, potential revenue loss, and abuse in public/shared environments.


Timeline

DateEvent
April 13, 2025Vulnerability discovered
April 16, 2025Reported to CSC ServiceWorks

Acknowledgment

Discoverer: Niranjan Gaire

  • CSC ServiceWorks Security Hall of Fame
  • MITRE CVE Record – CVE-2025-46018

Disclaimer

This repository is for documentation and responsible disclosure purposes only.
No exploit code or reproduction steps will be shared publicly.

Download Tool
June 4, 2025
CVE-2025-46018 assigned by MITRE
July 2025Vendor acknowledged issue fixed
Version 2.20.0Issue resolved in app update