ics-otregulatorNewsThe Broadside2 min read

PayRange Silent as CISA Flags 8.8 API Authorization Flaw

All versions are vulnerable, no patch exists, and the company hasn't responded to CISA coordination requests, facility managers across the U.S. and Canada are on their own to isolate payment systems.


TL;DR

CISA published an advisory for CVE-2026-18965, a missing authorization vulnerability in the PayRange API (CVSS 8.8) affecting all versions. The flaw allows unauthenticated attackers to access device inventory and configuration data, modify payment endpoints, or trigger denial-of-service conditions. Deployed in commercial facilities across the United States and Canada, PayRange has not responded to requests to coordinate mitigation, and no patch is available. CISA recommends network isolation and restricting internet exposure for affected systems.

The vulnerability itself is straightforward: management endpoints in the PayRange API lack proper authorization checks, making verbose device details publicly accessible with or without an account. An attacker who reaches these endpoints can read sensitive device information, arbitrarily modify devices, alter displayed images, or cause a denial of service. The CVSS v3.1 score of 8.8 reflects how little stands between an attacker and operational impact, network access and low privileges are enough.

What turns a routine ICS advisory into a story is the vendor's silence. CISA's advisory includes a single terse sentence: "PayRange has not responded to requests to work with CISA to mitigate this vulnerability." That's not a delay in patching. It's a refusal to engage with the coordinating agency while a high-severity flaw sits open in active deployments across critical infrastructure. CISA classifies PayRange under Commercial Facilities, one of the 16 critical infrastructure sectors. Payment terminals in laundromats, parking facilities, and vending operations run this API.

For municipal IT teams and facility managers, the advisory lands with no remediation timeline and no compensating control guidance from the vendor. CISA's recommended practices (isolating networks behind properly configured firewalls, with VPNs for any remote access) are sound but generic. They're the same recommendations appended to every ICS advisory. The difference here is that they're the only thing standing between an unauthenticated attacker and the ability to read or rewrite device configurations, because the vendor won't say when or if a fix is coming.

The advisory credits researcher Tahi Wilton Geary with reporting the vulnerability to CISA. No known public exploitation has been reported, but that's cold comfort when the attack surface is exposed by design and the vendor isn't talking.

Organizations running PayRange devices should isolate payment system networks from business networks, restrict internet-facing exposure of the API, and contact PayRange support directly at support@payrange.com to register demand for a patch. When a vendor goes silent, CISA can only publish the advisory, the leverage sits with the customers.


Published ·Deep Fathom

PayRange Silent as CISA Flags 8.8 API Authorization Flaw — The Broadside