CVE-2025-3329
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 319
CWE ID 310
Summary
CVE-2025-3329 is a newly identified vulnerability affecting Consumer Comanda Mobile versions up to 14.9.3.2 and 15.0.0.8. This issue lies within the Restaurant Order Handler component and is related to the handling of Login/Password arguments. Attackers can exploit this vulnerability to transmit sensitive information in cleartext within a local network. The complexity and exploitability of the attack are reported to be high, and an exploit has been made public.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.