Rbi operates a focused product line centered on its restaurant-business assistant application, which sits in the management and operational software space for food-service enterprises. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through authentication and data-handling weaknesses—including incorrect authorization, client-side authentication reliance, cleartext transmission of sensitive data, and exposure of private personal information—that reflect risks common to web-facing business applications handling customer and operational data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rbi over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62645CRITICAL The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the enti | Oct 17, 2025 | 9.9 | 33 | NO | NO |
CVE-2025-62650CRITICAL The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen. | Oct 17, 2025 | 9.9 | 31 | NO | NO |
CVE-2025-62643HIGH The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages. | Oct 17, 2025 | 8.6 | 27 | NO | NO |
CVE-2025-62642HIGH The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, allowing | Oct 17, 2025 | 8.6 | 27 | NO | NO |
CVE-2025-62646HIGH The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thr | Oct 17, 2025 | 7.7 | 25 | NO | NO |
CVE-2025-62644HIGH The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users. | Oct 17, 2025 | 7.7 | 25 | NO | NO |
CVE-2025-62651MEDIUM The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface. | Oct 17, 2025 | 5.8 | 20 | NO | NO |
CVE-2025-62649MEDIUM The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders. | Oct 17, 2025 | 5.8 | 20 | NO | NO |
CVE-2025-62648MEDIUM The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume. | Oct 17, 2025 | 5.8 | 20 | NO | NO |
CVE-2025-62647MEDIUM The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS | Oct 17, 2025 | 5.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rbi.
Media articles that mention a CVE ID that affects a product developed by Rbi — matched by CVE ID, not by vendor name.