Junglewise Threat Intelligence

CVE-2025-7016: Akın Software QR Menu improper access control

CVE-2025-7016 · Severity: high · CVSS 8 · Published 2026-01-29

Technologies: Akın Software Computer Import Export Industry and Trade Ltd. QR Menu.

Executive brief

Akın Software's QR Menu, a digital menu system used by restaurants and hospitality businesses, contains a security flaw in how it manages user permissions. An attacker could exploit this to bypass authentication and gain unauthorized access to the system's administrative or sensitive functions. This could lead to the unauthorized modification of menu data, exposure of business information, or disruption of restaurant operations.

Technical details

An improper access control vulnerability (CWE-284) in Akın Software QR Menu allows for authentication abuse. The flaw exists in the application's permission logic, enabling an attacker to bypass standard authentication checks. According to the CNA, the attack requires low privileges and some user interaction, though NIST's analysis suggests it may be exploitable without any privileges. Successful exploitation allows an attacker to gain unauthorized access to sensitive data or administrative functions. The vulnerability is resolved in version s1.05.12.

Affected products

  • Akın Software Computer Import Export Industry and Trade Ltd. QR Menu before s1.05.12

Timeline

  • 2026-01-29: disclosed
  • 2026-01-29: advisory
  • 2026-06-05: other: Advisory updated with enriched data

References