Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1000 CNY

100.0%

CVE-2025-62645 โ€” AI Deep Analysis Summary

CVSS 9.9 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: A critical flaw in the RBI Assistant Platform allows attackers to steal admin tokens via a GraphQL mutation.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: **CWE-266** (Incorrect Privilege Assignment). ๐Ÿ› **Flaw**: The `createToken` GraphQL mutation is misconfigured, granting excessive privileges to authenticated users without proper validation.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿข **Vendor**: Restaurant Brands International (RBI). ๐Ÿ” **Products**: Assistant Platform (used by Burger King, Popeyes, Tim Hortons). ๐Ÿ“… **Affected Versions**: All versions released **before 2025-09-06**.โ€ฆ

Q4What can hackers do? (Privileges/Data)

๐Ÿ”‘ **Privileges**: Escalates from standard user to **Full Administrator**. ๐Ÿ“‚ **Data Access**: Complete access to the entire platform backend. ๐Ÿš— **Real World**: Attackers can control drive-thru systems and customer data.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ” **Auth Required**: Yes, but **Low** (PR:L). ๐ŸŒ **Network**: Remote (AV:N). ๐Ÿ–ฑ๏ธ **User Interaction**: None (UI:N). ๐Ÿ“Š **Difficulty**: **Low** (AC:L). โšก **Verdict**: Easy to exploit for anyone with basic platform access.

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ”“ **Exploitation**: **Yes**, wild exploitation confirmed. ๐Ÿ“ฐ **Evidence**: Hackers publicly demonstrated control over drive-thrus and platforms.โ€ฆ

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Check**: Scan for the `createToken` GraphQL endpoint. ๐Ÿงช **Test**: Attempt to trigger the mutation with low-privilege credentials. ๐Ÿ“ก **Indicator**: Look for unexpected admin token generation in logs.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿ› ๏ธ **Fix**: Update to version **2025-09-06 or later**. โœ… **Official Patch**: RBI has acknowledged the issue and released a fix. ๐Ÿ“ฅ **Action**: Immediate upgrade required for all Assistant Platform instances.โ€ฆ

Q9What if no patch? (Workaround)

๐Ÿšง **Workaround**: Restrict access to the `createToken` mutation. ๐Ÿšซ **Block**: Disable GraphQL endpoints if possible. ๐Ÿ‘ฎ **Monitor**: Implement strict WAF rules for GraphQL traffic.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Priority**: **CRITICAL** (CVSS 9.8). ๐Ÿšจ **Urgency**: **Immediate Action Required**. โณ **Risk**: Active exploitation means zero-day window is closed. ๐Ÿƒ **Action**: Patch within 24 hours.โ€ฆ