Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm

Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm

SEC Consult identified a critical vulnerability in KioSoft’s NFC-based stored-value cards that allows attackers to artificially inflate balances. The company delayed over a year in releasing a firmware patch after being alerted to the issue, highlighting significant security lapses in RFID technology. #KioSoft #MiFareClassic #NFCVulnerability

Keypoints

  • KioSoft’s stored-value cards using MiFare Classic NFC technology are susceptible to hacking.
  • Researchers demonstrated that hackers can read, write, and manipulate card balances without online validation.
  • Exploiting this vulnerability enables the creation of virtually unlimited funds on affected cards.
  • It took KioSoft over a year to release a firmware patch after initial disclosure by SEC Consult.
  • The company has not publicly confirmed the impacted hardware versions or detailed patch information.

Read More: https://www.securityweek.com/payment-system-vendor-took-year-to-patch-infinite-card-top-up-hack-security-firm/