Metrics
Affected Vendors & Products
Thu, 01 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal. | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system. |
Metrics |
cvssV3_1
|
ssvc
|
Thu, 01 May 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system. | KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal. |
Title | KUNBUS Revolution Pi Missing Authentication for Critical Function | KUNBUS Revolution Pi Authentication Bypass by Primary Weakness |
Weaknesses | CWE-306 | CWE-305 |
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 01 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system. | |
Title | KUNBUS Revolution Pi Missing Authentication for Critical Function | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-05-01T18:37:37.244Z
Updated: 2025-05-01T19:00:44.088Z
Reserved: 2025-04-17T20:46:42.230Z
Link: CVE-2025-24522

Updated: 2025-05-01T18:45:12.250Z

Status : Received
Published: 2025-05-01T19:15:57.097
Modified: 2025-05-01T19:15:57.097
Link: CVE-2025-24522

No data.