VYPR
Vendor

KUNBUS

Products
6
CVEs
10
Across products
12
Status
Private

Products

6

Recent CVEs

10
  • CVE-2025-41646CriJun 6, 2025
    risk 0.67cvss 9.8epss 0.43

    An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device

  • CVE-2025-32011CriMay 1, 2025
    risk 0.65cvss 9.8epss 0.27

    KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.

  • CVE-2025-24522CriMay 1, 2025
    risk 0.65cvss 10.0epss 0.01

    KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying…

  • CVE-2019-6527CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.01

    PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.

  • CVE-2025-35996CriMay 1, 2025
    risk 0.59cvss 9.0epss 0.15

    KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape…

  • CVE-2019-6533CriFeb 12, 2019
    risk 0.59cvss 9.1epss 0.01

    Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).

  • CVE-2019-6531HigApr 2, 2019
    risk 0.53cvss 8.1epss 0.01

    An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) if the attacker is in an MITM position.

  • CVE-2019-6549HigFeb 12, 2019
    risk 0.47cvss 7.2epss 0.01

    An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.

  • CVE-2025-36558MedMay 1, 2025
    risk 0.41cvss 6.1epss 0.18

    KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.

  • CVE-2019-6529MedJan 7, 2020
    risk 0.32cvss 4.9epss 0.01

    An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166).