Path Traversal Vulnerability in KUNBUS RevPiPyLoad Product by Nozomi Networks
CVE-2026-57472

6.9MEDIUM

Key Information:

Vendor

Kunbus

Vendor
CVE Published:
14 August 2026

What is CVE-2026-57472?

A vulnerability exists in KUNBUS RevPiPyLoad's XML-RPC management interface that may allow an unauthenticated local attacker to exploit an improper pathname limitation. By sending carefully crafted requests to the management service, the attacker could potentially delete arbitrary files, compromising the integrity of configuration settings and leading to a denial of service scenario. This issue fundamentally arises from the mishandling of file paths within the file management functionality, posing significant risks if left unaddressed.

Affected Version(s)

RevPiPyLoad 0 <= 0.11.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Quagliarella at Nozomi Networks
.