Path Traversal in KUNBUS RevPiPyLoad by Nozomi Networks Labs
CVE-2026-57471

6.8MEDIUM

Key Information:

Vendor

Kunbus

Vendor
CVE Published:
14 August 2026

What is CVE-2026-57471?

A path traversal vulnerability exists in the XML-RPC management interface of KUNBUS RevPiPyLoad, as identified by Nozomi Networks Labs. This weakness allows a local attacker, without authentication, to send specially crafted requests to the management service, potentially gaining access to any files accessible by the RevPiPyLoad daemon. This may include sensitive configuration files and credential information, posing a significant risk to system integrity and confidentiality.

Affected Version(s)

RevPiPyLoad 0 <= 0.11.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Quagliarella at Nozomi Networks
.