Junglewise Threat Intelligence

CVE-2024-12925: Akınsoft QR Menü HTTP response splitting via certificate host mismatch

CVE-2024-12925 · Severity: high · CVSS 7.3 · Published 2025-09-01

Technologies: Akınsoft QR Menü. Vendors: Akınsoft.

Executive brief

Akınsoft QR Menü, a digital menu system used by restaurants and hospitality businesses, contains a security flaw in how it handles web communications. This vulnerability allows an attacker to manipulate the responses sent by the server to customers' browsers. If exploited, this could lead to the theft of user session information, the delivery of malicious content, or the redirection of customers to fraudulent websites.

Technical details

Akınsoft QR Menü versions s1.05.05 through v1.05.12 are vulnerable to HTTP Response Splitting. The root cause is an Improper Validation of Certificate with Host Mismatch (CWE-297), which allows an attacker to interfere with the application's HTTP response generation. By sending specially crafted requests, a remote, unauthenticated attacker can inject CRLF characters to split the HTTP response, potentially leading to Cross-Site Scripting (XSS), cache poisoning, or session hijacking. The vulnerability is exploitable over the network without user interaction. Users are advised to upgrade to version v1.05.12 or later.

Affected products

  • Akınsoft QR Menü s1.05.05 to v1.05.12

Timeline

  • 2025-09-01: advisory: Initial publication of CVE-2024-12925 by TR-CERT/USOM.

References

Related threats