Authentication Bypass Vulnerability in KUNBUS PiCtory Software
CVE-2025-32011
9.3CRITICAL
What is CVE-2025-32011?
The KUNBUS PiCtory software, specifically versions 2.5.0 to 2.11.1, is susceptible to an authentication bypass vulnerability. This flaw enables a remote attacker to exploit path traversal techniques, potentially allowing unauthorized access to sensitive areas of the application. It is crucial for users of this software to apply necessary patches and update to secure versions to mitigate this threat.
Affected Version(s)
Revolution Pi PiCtory 2.5.0 <= 2.11.1
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adam Bromiley of Pen Test Partners reported these vulnerabilities to CISA.