ZeroHour

CVE-2025-32011

large

Authentication Bypass via Path Traversal in KUNBUS PiCtory

CVSS 4.0
9.3 critical
EPSS
27%p98
Published
()
Modified
AI analysis

KUNBUS PiCtory versions 2.5.0 through 2.11.1, the web-based configuration tool bundled with KUNBUS Revolution Pi (RevPi) industrial controllers, contain an authentication bypass flaw (CWE-305) caused by a path traversal weakness. A remote, unauthenticated attacker can send crafted HTTP requests containing path-traversal sequences to the PiCtory web interface and bypass authentication without any user interaction. The attacker thereby gains access to the device's configuration application without valid credentials, and the critical CVSS 4.0 score of 9.3 reflects high potential impact to the confidentiality, integrity, and availability of the affected device. Affected users are operators of Revolution Pi installations running the affected PiCtory versions, especially where the web interface is reachable from the internet or from a broader corporate network. No public proof-of-concept or confirmed in-the-wild exploitation is known and the issue is not in CISA's KEV catalog, but EPSS assigns an elevated 27.3% probability of exploitation within 30 days (98th percentile).

What to do: Upgrade PiCtory to a release later than 2.11.1, checking the KUNBUS/CISA ICS advisory for the exact fixed version before deploying. Restrict the PiCtory web interface so it is not reachable from the internet or untrusted networks, and review device logs and stored configuration for signs of unauthenticated access or tampering.

Affected
KUNBUS PiCtory2.5.0 through 2.11.1
Estimated exposure
large~100,000+ RevPi devices in the field (PiCtory ships by default on KUNBUS Revolution Pi controllers) — Estimate: PiCtory is preinstalled on every KUNBUS Revolution Pi (RevPi) controller, whose cumulative installed base has been publicly cited in the six figures, and the affected 2.5.0-2.11.1 range covers the current 2.x release line, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.

Weakness
CWE-305
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news