Researchers disclosed multiple vulnerabilities in the Italretail SpiceT Android-based fiscal printer that allowed unauthorized fiscal operations, including printing fake receipts, opening the cash drawer, and tampering with the device’s Electronic Journal (DGFE). The core issue was that Android applications could directly access the fiscal unit through the world-readable and writable device interface /dev/ttymxc4, while weak SELinux controls failed to isolate untrusted apps. Shielder reported that undocumented CUSTOM protocol commands could be abused to interleave fraudulent receipts with legitimate transactions and to delete, write, or overwrite files stored in the supposedly append-only DGFE memory.
A second part of the research described a remote exploit chain against the default ItalRetail RistorAndro point-of-sale application running on the printer. An unauthenticated web server on port 12312 exposed a /write endpoint vulnerable to path traversal and arbitrary file write, allowing attackers on the same LAN to place malicious APKs in the auto-update directory and trigger installation. Combined with Android 6 privilege-escalation flaws including CVE-2017-13156 and CVE-2016-5195, the chain could lead from remote code execution to system-level compromise and ultimately root, enabling full takeover of the fiscal printer and fraudulent fiscal record manipulation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Shielder published the second part of its research describing a remote exploit chain against the SpiceT fiscal printer via the default RistorAndro POS application. The chain used an unauthenticated file-write flaw and Android privilege-escalation bugs to achieve remote takeover and potentially root access.
Shielder publicly disclosed the first part of its research on the SpiceT fiscal printer, detailing how installed Android apps could abuse access to the fiscal unit to print fake receipts, manipulate DGFE records, and perform other unauthorized operations.
Shielder reported multiple vulnerabilities in the Italretail SpiceT Android-based fiscal printer to Italretail in September 2020. The issues included unauthorized access to fiscal functions and the ability for apps to communicate directly with the fiscal unit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
shielder.com
Open sourceshielder.com
Open sourcesecuritytxt.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.