#KioSoft
Payment System Vendor Took Year+ To Patch Infinite Card Top-Up Hack: Security Firm - https://mwyr.es/5QzrTl87 #securityweek #infosec
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm
KioSoft was notified about a serious NFC card vulnerability in 2023 and only recently claimed to have released a patch.
mwyr.es
September 15, 2025 at 1:09 AM
Notícia da SecurityWeek

"Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm" #bolhasec
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm
Payment solutions company KioSoft took a long time to address a serious vulnerability affecting some of its NFC-based cards.
www.securityweek.com
November 10, 2025 at 6:30 PM
SEC Consult SA-20250908-0 :: NFC Card Vulnerability Exploitation Leading to Free Top-Up in KioSoft "Stored Value" Unattended Payment Solution (Mifare)

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 08SEC Consult Vulnerability Lab Security Advisory < 20250908-0…

#hackernews #news
SEC Consult SA-20250908-0 :: NFC Card Vulnerability Exploitation Leading to Free Top-Up in KioSoft "Stored Value" Unattended Payment Solution (Mifare)
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 08SEC Consult Vulnerability Lab Security Advisory < 20250908-0 > ======================================================================= title: NFC Card Vulnerability Exploitation Leading to Free Top-Up product: KioSoft "Stored Value" Unattended Payment Solution (Mifare) vulnerable version: Current firmware/hardware as of Q2/2025 fixed version: No version numbers available CVE number:...
seclists.org
September 9, 2025 at 8:50 PM
Alarming Security Flaw in KioSoft NFC Payment Cards Exposes Millions to Fraud

Introduction In today’s fast-paced digital payment world, security is more critical than ever. However, a recent discovery by cybersecurity experts has unveiled a glaring vulnerability in KioSoft’s NFC-based payment…
Alarming Security Flaw in KioSoft NFC Payment Cards Exposes Millions to Fraud
Introduction In today’s fast-paced digital payment world, security is more critical than ever. However, a recent discovery by cybersecurity experts has unveiled a glaring vulnerability in KioSoft’s NFC-based payment cards, putting millions of transactions at risk. This flaw highlights how even widely deployed payment systems can be compromised if proper security measures are delayed. KioSoft’s Payment System Under Fire KioSoft, a Florida-based company with offices in seven countries, manufactures self-service payment kiosks used in laundromats, vending machines, arcades, and car washes.
undercodenews.com
September 12, 2025 at 12:29 PM
🟢 Vendor spent a year fixing a flaw that allowed unlimited top-ups of NFC cards

🗨️ Security researchers from SEC Consult, part of Eviden, reported that the payments company KioSoft spent more than a…

#news
Vendor spent a year fixing a flaw that allowed unlimited top-ups of NFC cards
Read more
hackmag.com
March 21, 2026 at 2:40 PM
Feed: "Payments Dive - Latest News"
By: Lynne Marek on Tuesday, December 2, 2025
PayRange buys rival KioSoft
The two payments companies in the unattended retail arena ended a four-year legal battle last year, and now one is falling into the other’s arms.
www.paymentsdive.com
December 2, 2025 at 9:51 PM
Feed: "FinSMEs"
Published on Monday, December 1, 2025
PayRange to Acquire KioSoft
PayRange, a Portland, Oregon-based commerce platform for unattended retail, acquired KioSoft Technologies, a global provider of cashless payment and IoT solutions
www.finsmes.com
December 2, 2025 at 8:07 AM
PayRange adquiere KioSoft y transforma el retail desatendido con IoT
PayRange adquiere KioSoft y transforma el retail desatendido con IoT
PayRange LLC, plataforma líder en comercio para el retail desatendido, anunció hoy la adquisición...
internetdelascosas.xyz
December 2, 2025 at 10:24 AM
CVE-2025-8699 - KioSoft Stored Value Unattended Payment Solution NFC Card Cash Value Manipulation Vulnerability
CVE ID : CVE-2025-8699

Published : Sept. 12, 2025, 12:15 p.m. | 2 hours, 28 minutes ago

Description : Some "Stored Value" Unattended Payment Solutions of KioSo...
CVE-2025-8699 - KioSoft Stored Value Unattended Payment Solution NFC Card Cash Value Manipulation Vulnerability
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure MiFare Classic NFC card and can be read and written back. By carefully observing …
cvefeed.io
September 12, 2025 at 2:46 PM
February 12, 2024 at 12:10 PM
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm

KioSoft was notified about a serious NFC card vulnerability in 2023 and only recently claimed to have released a patch. The post Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm…
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm
KioSoft was notified about a serious NFC card vulnerability in 2023 and only recently claimed to have released a patch. The post Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm appeared first on SecurityWeek.
www.securityweek.com
September 12, 2025 at 8:44 AM
📌 Critical NFC Vulnerability Allows Infinite Card Recharging, KioSoft Releases Patch After Year-Long Delay https://www.cyberhub.blog/article/13109-critical-nfc-vulnerability-allows-infinite-card-recharging-kiosoft-releases-patch-after-year-long-delay
Critical NFC Vulnerability Allows Infinite Card Recharging, KioSoft Releases Patch After Year-Long Delay
KioSoft, a payment system vendor, was informed in 2023 about a serious vulnerability in NFC cards that allowed for infinite recharging. This vulnerability affected systems using NFC technology and MiFare cards, potentially leading to significant financial losses. The flaw enabled attackers to recharge cards indefinitely, impacting both users and businesses relying on these payment systems. KioSoft has recently released a patch to address this vulnerability. The vulnerability highlights the risks associated with NFC-based payment systems, which are widely used for their convenience. The delay in patching the vulnerability, taking a year, underscores the challenges in timely vulnerability management. This delay could have exposed users to prolonged risks of financial exploitation. From a technical standpoint, the vulnerability likely exploits weaknesses in the card's authentication or transaction validation mechanisms. NFC and MiFare cards are commonly used in public transportation, access control, and contactless payments, making this vulnerability particularly concerning due to its broad applicability. For cybersecurity professionals, this incident serves as a reminder of the importance of regular security audits and prompt patching. It also emphasizes the need for robust security measures in payment systems to prevent unauthorized transactions. Organizations using NFC-based payment systems should ensure that their systems are updated with the latest patches and conduct thorough security assessments to identify and mitigate similar vulnerabilities. The impact of this vulnerability extends beyond financial losses. It could erode trust in NFC-based payment systems, leading to a broader shift in consumer behavior and preferences. Cybersecurity professionals must stay vigilant and proactive in addressing such vulnerabilities to maintain the integrity and trustworthiness of payment systems.
www.cyberhub.blog
September 13, 2025 at 1:20 PM
PayRange buys rival KioSoft

The two payments companies in the unattended retail arena ended a four-year legal battle last year, and now one is falling into the other’s arms.

www.paymentsdive.com/news/payrang...

#FinTech #FinServ #Banking #Payments #PayTech
PayRange buys rival KioSoft
The two payments companies in the unattended retail arena ended a four-year legal battle last year, and now one is falling into the other’s arms.
www.paymentsdive.com
December 4, 2025 at 5:02 PM
CenterEdge Play: A Revolutionary Cashless Solution for Family Entertainment Centers#USA#Orlando#Payroc#CenterEdge#KioSoft
CenterEdge Play: A Revolutionary Cashless Solution for Family Entertainment Centers
Discover CenterEdge Play, an integrated cashless solution by CenterEdge and KioSoft, designed to enhance family entertainment centers through seamless transactions.
third-news.com
November 17, 2025 at 3:34 PM
[Avances en tecnología y comunicaciones]
[02-12-25] PayRange adquiere KioSoft y transforma el retail desatendido con IoT #IoT #InternetDeLasCosas
PayRange adquiere KioSoft y transforma el retail desatendido con IoT
PayRange LLC, plataforma líder en comercio para el retail desatendido, anunció hoy la adquisición...
internetdelascosas.xyz
December 2, 2025 at 11:23 AM
決済システムベンダー、無限カードチャージ脆弱性の修正に1年以上:セキュリティ企業

サイバーセキュリティコンサルティング企業であるSEC Consult(Eviden傘下)は、決済ソリューション企業KioSoftが、NFCベースのカードの一部に影響する重大な脆弱性への対応に長い時間を要したと述べています。…
決済システムベンダー、無限カードチャージ脆弱性の修正に1年以上:セキュリティ企業
サイバーセキュリティコンサルティング企業であるSEC Consult(Eviden傘下)は、決済ソリューション企業KioSoftが、NFCベースのカードの一部に影響する重大な脆弱性への対応に長い時間を要したと述べています。 KioSoftは、コインランドリー、ゲームセンター、自動販売機、洗車場など向けの無人セルフサービス決済機を製造しています。同社はフロリダ州に本社を置き、世界7カ国にオフィスを構えています。公式ウェブサイトによれば、35カ国で41,000台以上のキオスク端末と160万台の決済端末を展開しているとされています。 SEC Consultの研究者は2023年に、KioSoftの一部のストアドバリューカード(特定の決済端末で利用するために顧客がチャージするデジタルウォレット)が、無料で残高をチャージできる脆弱性(CVE-2025-8699)の影響を受けていることを発見しました。このハッキングは、残高が安全なオンラインデータベースではなくカード本体にローカル保存されていることに依存しています。 SEC Consultが特定した影響を受けるカードは、重大なセキュリティ問題が知られているMiFare Classic NFCカード技術を利用していました。 既知のMiFareカードの脆弱性を基に、カード上のデータの保存方法を分析した結果、SEC Consultの研究者はカードからデータを読み取り、書き込むことに成功し、「何もないところからお金を作り出す」ことができました。ハッカーはカードの残高を最大655ドルまで増やすことができ、このプロセスは繰り返し実行可能だと、SEC ConsultのJohannes Greil氏はSecurityWeekに語っています。 攻撃者は、RFIDセキュリティ分析や研究開発用に設計されたProxmarkのようなハードウェアツールを使って攻撃を行うことができます。また、MiFareカードの脆弱性についての知識も必要だとGreil氏は説明しています。 SEC Consultは今週、自社の研究内容を説明するアドバイザリを公開しました。同社はKioSoftとのやり取りの詳細なタイムラインも公開しており、ベンダーが修正パッチをリリースするまでに1年以上かかったことが明らかになっています。 セキュリティ企業は2023年10月に初めてKioSoftに連絡しましたが、カーネギーメロン大学ソフトウェア工学研究所のCERTコーディネーションセンターが関与するまで、ベンダーからの返答はありませんでした。 広告。スクロールして記事の続きをお読みください。 SEC Consultは2023年10月以降、進捗状況の更新を何度も依頼したものの、多くは返答がなかったと主張しています。タイムラインによれば、ベンダーは情報公開期限の延長を複数回要請し、最終的には2025年夏にファームウェアパッチをリリースしたとセキュリティ企業に通知しました。今後、新しいハードウェアも展開される予定だとしています。 KioSoftは、影響を受けるバージョンや修正済みバージョンの番号を提供することを拒否し、影響を受ける顧客には個別に通知すると主張したとセキュリティ企業は述べています。KioSoftの製品は広く利用されていますが、同社はSEC Consultに対し、ほとんどのソリューションでは脆弱なMiFareカード技術は使用されていないと説明しました。 SEC Consultは、当初調査に使用した端末へのアクセス権をすでに失っており、ベンダーのパッチを検証できていません。 KioSoftはSecurityWeekのコメント要請に応じていません。 翻訳元:
blackhatnews.tokyo
September 12, 2025 at 8:48 AM
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm KioSoft was notified about a serious NFC card vulnerability in 2023 and only recently claimed to have released a p...

#Vulnerabilities #Featured #hardware #KioSoft #MiFare […]

[Original post on securityweek.com]
Original post on securityweek.com
www.securityweek.com
September 12, 2025 at 9:05 AM
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm www.securityweek.com/payment-syst...
Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm
KioSoft was notified about a serious NFC card vulnerability in 2023 and only recently claimed to have released a patch.
www.securityweek.com
September 13, 2025 at 11:42 PM
NFC Card Hack: Top Up Like a Pro (But Seriously, Don’t)

NFC Card hack lets you top-up for free in KioSoft's payment system. Discover the vulnerability and how to avoid it. Secure your funds now!
thenimblenerd.com?p=1054990
NFC Card Hack: Top Up Like a Pro (But Seriously, Don’t)
The NFC card vulnerability in KioSoft's "Stored Value" Unattended Payment Solution allows tech-savvy individuals to "create money out of thin air." With a little manipulation, users can top up their cards for free. It's a modern-day magic trick that KioSoft probably wishes remained in its hat.
thenimblenerd.com
September 9, 2025 at 1:25 AM