Authentication Bypass Vulnerability in KUNBUS PiCtory Software
CVE-2025-32011

9.3CRITICAL

Key Information:

Vendor
CVE Published:
1 May 2025

What is CVE-2025-32011?

The KUNBUS PiCtory software, specifically versions 2.5.0 to 2.11.1, is susceptible to an authentication bypass vulnerability. This flaw enables a remote attacker to exploit path traversal techniques, potentially allowing unauthorized access to sensitive areas of the application. It is crucial for users of this software to apply necessary patches and update to secure versions to mitigate this threat.

Affected Version(s)

Revolution Pi PiCtory 2.5.0 <= 2.11.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Bromiley of Pen Test Partners reported these vulnerabilities to CISA.
.