CVE-2025-9902
7.5AKIN Software · QRMenu
An authorization bypass vulnerability exists in AKIN Software QRMenu due to a user-controlled key, allowing unauthenticated attackers to perform privilege abuse.
Executive summary
An authorization bypass vulnerability in AKIN Software QRMenu allows unauthenticated attackers to gain unauthorized access to system data, posing a significant risk to organizational confidentiality.
Vulnerability
The software suffers from an authorization bypass via user-controlled keys (CWE-639), which permits an unauthenticated attacker to manipulate parameters to access restricted resources or perform unauthorized actions. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that this flaw is remotely exploitable without requiring user interaction or prior authentication.
Business impact
The ability for an unauthenticated attacker to bypass authorization mechanisms can lead to the unauthorized disclosure of sensitive business information or the compromise of administrative functions. Given the CVSS score of 7.5, this vulnerability is categorized as High severity, necessitating prompt remediation to prevent potential data breaches and unauthorized system manipulation.
Remediation
Immediate Action: Review the official USOM security advisory for the latest patch availability and apply the update to version dated 05.09.2025 or later.
Proactive Monitoring: Monitor server access logs for anomalous, high-frequency requests or unauthorized attempts to access administrative endpoints by non-privileged accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns targeting key-based authorization parameters until a permanent patch is verified and deployed.
Exploitation status
Public Exploit Available: Unknown (no confirmed public exploit)
Analyst recommendation
Organizations utilizing AKIN Software QRMenu must treat this vulnerability with high priority due to the ease of exploitability and the lack of required authentication. Administrators should verify their current version and coordinate with the vendor immediately to obtain the necessary security updates to close this authorization gap.
More AKIN Software CVEs
Sources
Originally found and disclosed by Berat ARSLAN, per the CVE Program record.