Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Credit Card Payment Terminal Exploited for Remote Access

A security vulnerability has been identified in the Worldline Yomani XR payment terminal, a device frequently used in various retail environments across Switzerland. This vulnerability allows attackers to gain control over the terminal within a short…

A security vulnerability has been identified in the Worldline Yomani XR payment terminal, a device frequently used in various retail environments across Switzerland. This vulnerability allows attackers to gain control over the terminal within a short period.

The Yomani XR, although designed as a tamper-protected device, has an unsecured root shell accessible through its maintenance port. This exposure grants remote access to anyone with brief physical access to the terminal.

Unlocked Root Shell and Accessible Debug Port

An internal analysis has revealed an unpopulated debug connector concealed behind a service hatch on the terminal's back panel. By connecting a serial cable and powering the terminal, a standard Linux boot log becomes visible.

The system operates on a 3.6 kernel built with Buildroot, featuring BusyBox utilities and uClibc libraries. A login prompt appears on the serial console after booting. Entering "root" provides full root shell access without requiring a password.

This vulnerability allows attackers to gain control over the terminal within a short period.
Derek Vaughn · Thehackingpost

This access could potentially allow attackers to install malware, capture transaction data, or access back-end networks. Despite the device's sophisticated engineering, including a custom dual-core Arm ASIC and extensive tamper detection features, the debug interface remains unprotected.

The terminal utilizes two distinct processing environments. The first core runs an "insecure" Linux application for network communication and business logic, while a second, secure core manages card reader operations. This secure core only functions if tamper protections are intact and is not directly affected by the unsecured shell access.

However, compromising the application core can still lead to significant risks, such as interfering with updates or installing backdoors. Although there is no public evidence of data theft via this vulnerability, the exposure of an unprotected root shell is a significant security concern.

Advertisement

Merchants using these terminals should inspect their devices for unauthorized access and request firmware updates from vendors to deactivate the external debug port. Worldline has reportedly addressed this issue in subsequent firmware releases, but until these updates are fully implemented, operators remain at risk.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories