Unauthorized Remote Access Vulnerability in Kunbus Device
CVE-2025-41646

9.8CRITICAL

Key Information:

Vendor

Kunbus

Vendor
CVE Published:
6 June 2025

What is CVE-2025-41646?

An unauthorized remote attacker could exploit a vulnerability in Kunbus software by leveraging an incorrect type conversion, enabling them to bypass authentication mechanisms. This flaw poses a significant risk as it allows the attacker to gain unauthorized access and fully compromise the affected device.

Affected Version(s)

Revolution Pi webstatus 0.0.0 <= 2.4.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ajay Anto
.
CVE-2025-41646 : Unauthorized Remote Access Vulnerability in Kunbus Device