Executive brief
Akinsoft MyRezzta, a restaurant management and reservation system, contains a security flaw that fails to limit repeated login attempts. This allows an unauthorized person to potentially bypass security controls and gain access to the system by guessing credentials. Such an exploit could lead to the exposure of customer data, disruption of business operations, and unauthorized access to sensitive management functions.
Technical details
Akinsoft MyRezzta is vulnerable to an authentication bypass due to improper restriction of excessive authentication attempts (CWE-307). The vulnerability exists in versions s2.03.01 through v2.05.01. A remote, unauthenticated attacker can exploit this by performing brute-force or credential stuffing attacks without being blocked by rate-limiting or lockout mechanisms. Successful exploitation allows the attacker to gain unauthorized access to the application with high impact on confidentiality and moderate impact on integrity and availability. Users are advised to upgrade to version v2.05.01 or later.
Affected products
- Akinsoft MyRezzta from s2.03.01 before v2.05.01
Timeline
- 2025-09-03: advisory: Initial publication of CVE-2025-2415 by TR-CERT (USOM)
- 2025-09-03: disclosed