VYPR
Vendor

KUNBUS

Products
8
CVEs
16
Across products
18
Status
Private

Products

8

Recent CVEs

16
  • CVE-2025-41646CriJun 6, 2025
    risk 0.67cvss 9.8epss 0.52

    An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device

  • CVE-2025-32011CriMay 1, 2025
    risk 0.65cvss 9.8epss 0.27

    KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.

  • CVE-2025-24522CriMay 1, 2025
    risk 0.65cvss 10.0epss 0.01

    KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying…

  • CVE-2019-6527CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.01

    PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.

  • CVE-2025-35996CriMay 1, 2025
    risk 0.59cvss 9.0epss 0.17

    KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape…

  • CVE-2019-6533CriFeb 12, 2019
    risk 0.59cvss 9.1epss 0.01

    Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).

  • CVE-2019-6531HigApr 2, 2019
    risk 0.53cvss 8.1epss 0.01

    An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) if the attacker is in an MITM position.

  • CVE-2026-13197HigAug 14, 2026
    risk 0.47cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local…

  • CVE-2026-13196HigAug 14, 2026
    risk 0.47cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside…

  • CVE-2019-6549HigFeb 12, 2019
    risk 0.47cvss 7.2epss 0.01

    An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.

  • CVE-2026-57472MedAug 14, 2026
    risk 0.45cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local…

  • CVE-2026-57471MedAug 14, 2026
    risk 0.44cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local…

  • CVE-2025-36558MedMay 1, 2025
    risk 0.41cvss 6.1epss 0.19

    KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.

  • CVE-2026-13198MedAug 14, 2026
    risk 0.38cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to corrupt…

  • CVE-2026-57469MedAug 14, 2026
    risk 0.33cvss —epss 0.00

    Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a remote unauthenticated attacker to perform state-changing operations in the context of an…

  • CVE-2019-6529MedJan 7, 2020
    risk 0.32cvss 4.9epss 0.01

    An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166).