Executive brief
The Restajet Online Food Delivery System, used by businesses to manage customer orders, contains a security flaw in its authentication process. This vulnerability allows an attacker to repeatedly attempt to guess passwords or recovery codes without being blocked. If exploited, an unauthorized person could take over customer or administrator accounts, potentially leading to the theft of personal data or disruption of business operations.
Technical details
A vulnerability classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) exists in the Restajet Online Food Delivery System through version 19122025. The application fails to implement adequate rate limiting or account lockout mechanisms on authentication endpoints, specifically affecting the password recovery workflow. A remote, unauthenticated attacker can exploit this by brute-forcing recovery tokens or passwords over the network. Successful exploitation allows for full account takeover. As of the disclosure date, the vendor has not responded to notifications, and no official patch has been confirmed.
Affected products
- Restajet Information Technologies Inc. Online Food Delivery System through 19122025
Timeline
- 2025-12-19: disclosed: Initial disclosure by TR-CERT (USOM)
- 2025-12-19: advisory: NVD publication date