Executive brief
PanCafe Pro, a management software used for internet cafes and gaming centers, contains a security flaw where sensitive data is transmitted without encryption. This allows an attacker on the same local network to intercept private information or disrupt the service through flooding attacks. Such an exploit could lead to the exposure of customer data or a complete shutdown of the cafe's management operations.
Technical details
PanCafe Pro versions prior to 3.3.2 (up to version 23092025) are vulnerable to CWE-319 (Cleartext Transmission of Sensitive Information). The application fails to encrypt sensitive data during transmission, allowing an unauthenticated attacker on the adjacent network to capture traffic. Furthermore, the vulnerability facilitates 'flooding' attacks, which can impact the availability of the service. The CVSS score of 8.3 reflects high impact on confidentiality and availability with low attack complexity, though it requires the attacker to be on the same local network (Adjacent vector).
Affected products
- Pan Software & Information Technologies Ltd. PanCafe Pro < 3.3.2 through 23092025
Timeline
- 2026-02-11: advisory: Initial publication of CVE-2025-10174 by USOM/TR-CERT
- 2026-06-05: other: CVE record modified with updated reference links