CVE-2025-3329
Severity CVSS v4.0:
LOW
Type:
CWE-310
Cryptographic Issues
Publication date:
07/04/2025
Last modified:
08/04/2025
Description
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to cleartext transmission of sensitive information. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
3.10
Severity 3.x
LOW
Base Score 2.0
1.80
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:consumer:comanda_mobile:*:*:*:*:*:*:*:* | 14.7.1.4 (including) | 15.0.0.8 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://medium.com/@davimouar/from-order-to-exploit-a-deep-dive-into-restaurant-network-security-64aeaf3a6f64
- https://vuldb.com/?ctiid.303543
- https://vuldb.com/?id.303543
- https://vuldb.com/?submit.551790
- https://medium.com/@davimouar/from-order-to-exploit-a-deep-dive-into-restaurant-network-security-64aeaf3a6f64
- https://vuldb.com/?submit.551790



