Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-41646 | Authentication Bypass via Incorrect Type Conversion in KUNBUS RevPi Status CVE-2025-41646 is a critical authentication bypass in the KUNBUS RevPi Status software package, caused by an incorrect type conversion (CWE-704). An unauthenticated remote attacker can trigger the flawed conversion over the network, without any privileges or user interaction, and thereby bypass the package's authentication entirely. Successful exploitation grants full control of the affected device, compromising confidentiality, integrity, and availability. Affected parties are operators of KUNBUS Revolution Pi (RevPi) industrial devices running the RevPi Status package, with specific version ranges not provided in the source data. As of now there is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation, though the 51.5% EPSS score (99th percentile) indicates a high probability of exploitation within the next 30 days. Do: Inventory RevPi devices for the RevPi Status package and, until a vendor update is applied, restrict network access to the service from untrusted networks. Apply the patched version as published in the VDE CERT advisory for CVE-2025-41646 (fixed versions are not specified in the source data), and monitor for a public exploit given the elevated EPSS score. | 9.8 | 52% |
| moderate≈1,000–10,000 systems plausibly affected (public internet scans show RevPi devices in the low thousands; total deployments, including air-gapped OT networks,… | ||
| CVE-2019-6529 | An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166). An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166). NVD description · AI analysis pending | 4.9 | 1% |
| — | ||
| CVE-2019-6531 | An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.1316 An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) if the attacker is in an MITM position. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2019-6527 | PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted. NVD description · AI analysis pending | 9.8 group max | 1% |
| — |