Credit Card Payment Terminal Exploited for Remote Access
A security vulnerability has been identified in the Worldline Yomani XR payment terminal, a device frequently used in various retail environments across Switzerland. This vulnerability allows attackers to gain control over the terminal within a short…
A security vulnerability has been identified in the Worldline Yomani XR payment terminal, a device frequently used in various retail environments across Switzerland. This vulnerability allows attackers to gain control over the terminal within a short period.
The Yomani XR, although designed as a tamper-protected device, has an unsecured root shell accessible through its maintenance port. This exposure grants remote access to anyone with brief physical access to the terminal.
Unlocked Root Shell and Accessible Debug Port
An internal analysis has revealed an unpopulated debug connector concealed behind a service hatch on the terminal's back panel. By connecting a serial cable and powering the terminal, a standard Linux boot log becomes visible.
The system operates on a 3.6 kernel built with Buildroot, featuring BusyBox utilities and uClibc libraries. A login prompt appears on the serial console after booting. Entering "root" provides full root shell access without requiring a password.
This vulnerability allows attackers to gain control over the terminal within a short period.
This access could potentially allow attackers to install malware, capture transaction data, or access back-end networks. Despite the device's sophisticated engineering, including a custom dual-core Arm ASIC and extensive tamper detection features, the debug interface remains unprotected.
The terminal utilizes two distinct processing environments. The first core runs an "insecure" Linux application for network communication and business logic, while a second, secure core manages card reader operations. This secure core only functions if tamper protections are intact and is not directly affected by the unsecured shell access.
However, compromising the application core can still lead to significant risks, such as interfering with updates or installing backdoors. Although there is no public evidence of data theft via this vulnerability, the exposure of an unprotected root shell is a significant security concern.
Merchants using these terminals should inspect their devices for unauthorized access and request firmware updates from vendors to deactivate the external debug port. Worldline has reportedly addressed this issue in subsequent firmware releases, but until these updates are fully implemented, operators remain at risk.
Based on reporting by GBHackers.
