Executive brief
Akinsoft QR Menu, a digital menu system used by restaurants and hospitality businesses, contains a security flaw that fails to limit repeated login attempts. This allows an unauthorized person to potentially bypass security controls and gain access to the system by guessing credentials. Such an exploit could lead to unauthorized changes to menu pricing, access to customer data, or disruption of restaurant operations.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the Akinsoft QR Menu software. The root cause is a lack of rate limiting or account lockout mechanisms on authentication endpoints, which allows an attacker to perform brute-force or credential stuffing attacks. This is a network-based attack that requires no prior authentication or user interaction. Successful exploitation enables an attacker to bypass authentication and gain unauthorized access to the application's administrative or user functions. The issue is fixed in version v1.05.12.
Affected products
- Akinsoft QR Menu from s1.05.07 before v1.05.12
Timeline
- 2025-09-01: disclosed
- 2025-09-01: advisory