
Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4"
A payment authentication bypass vulnerability was discovered in the CSC Pay Mobile App, affecting version 2.19.4. The flaw allowed an attacker to initiate a payment, disable Bluetooth at a specific point in the process, and activate a laundry machine without being charged.
This issue has been responsibly disclosed and is now tracked as CVE-2025-46018.
Impact: Unauthorized use of machines without payment, potential revenue loss, and abuse in public/shared environments.
| Date | Event |
|---|---|
| April 13, 2025 | Vulnerability discovered |
| April 16, 2025 | Reported to CSC ServiceWorks |
Discoverer: Niranjan Gaire
This repository is for documentation and responsible disclosure purposes only.
No exploit code or reproduction steps will be shared publicly.
| June 4, 2025 |
| CVE-2025-46018 assigned by MITRE |
| July 2025 | Vendor acknowledged issue fixed |
| Version 2.20.0 | Issue resolved in app update |