Subscribe to our email list for the latest news and updates from iMin.
Security Advisory 2222
This is a deliberate test submission used to validate the intake, acknowledgement and PSIRTrouting of this form. It is NOT a real finding. Please close it as a drill after verification.
Test scenario used for the drill:
The shipping firmware image leaves the Android Debug Bridge daemon listening on TCP port 5555,with authorisation disabled (ro.adb.secure=0, persist.adb.tcp.port=5555). Any host on the same,shop LAN can therefore connect without pairing confirmation, install or replace packages, read,application data belonging to the payment UI, and obtain a shell running as the system user.No physical access and no credentials are required.
Steps to reproduce:
1. Power on a Swan 1 terminal with firmware 1.4.2 and connect it to a shop Wi-Fi network.
2. From any host on the same subnet, determine the terminal’s IP from the DHCP lease table.
3. Run: adb connect :5555The connection is accepted immediately; no confirmation dialog appears on the terminal.
4. Run: adb shell id Expected (hardened build): connection refused, or a pairing prompt on the device.
Observed (this build): uid=1000(system) gid=1000(system) — shell obtained.
5. Run: adb shell pm list packages | grep pay
The payment application package is listed and its data directory is readable.

tsconfig.json






















