CVE-2025-7013
Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers.
This issue affects Menu Panel: through 29012026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access80 % - Impacto secundario
T1005Data from Local Systemcollection70 % - Impacto secundario
T1565.001Stored Data Manipulationimpact75 %
CWE-639 es authorization bypass mediante claves controladas por usuario. Vector AV:N sin autenticación (PR:N) indica red sin privilegios (T1190). El impacto C:H/I:H/A:H permite acceso no autorizado a cuentas (T1078.001), modificación de datos (T1565.001) y lectura de información sensible (T1005).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-639
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-7013",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7013",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-01-29T15:56:15.504084Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "iletisim@usom.gov.tr",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "iletisim@usom.gov.tr",
"affectedData": [
{
"vendor": "QR Menu Pro Smart Menu Systems",
"product": "Menu Panel",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "29012026"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-01-29T14:16:12.683",
"references": [
{
"url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0007",
"source": "iletisim@usom.gov.tr"
},
{
"url": "https://www.usom.gov.tr/bildirim/tr-26-0007",
"tags": [
"Third Party Advisory"
],
"source": "iletisim@usom.gov.tr"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "iletisim@usom.gov.tr",
"description": [
{
"lang": "en",
"value": "CWE-639"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers.\n\nThis issue affects Menu Panel: through 29012026. \n\nNOTE: The vendor was contacted early about this disclosure but did not respond in any way."
},
{
"lang": "es",
"value": "Vulnerabilidad de elusión de autorización mediante clave controlada por el usuario en el Panel de Menú de los Sistemas de Menú Inteligentes QR Menu Pro permite la explotación de identificadores de confianza. Este problema afecta al Panel de Menú: hasta el 29012026.\n\nNOTA: Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera."
}
],
"lastModified": "2026-06-17T10:04:05.850",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qrmenumpro:menu_panel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7097939F-C013-424F-A7EF-AE5EE7C867F1",
"versionEndIncluding": "29012026"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "iletisim@usom.gov.tr"
}