Path Traversal Vulnerability in KUNBUS RevPiPyLoad Product by Nozomi Networks
CVE-2026-57472
6.9MEDIUM
What is CVE-2026-57472?
A vulnerability exists in KUNBUS RevPiPyLoad's XML-RPC management interface that may allow an unauthenticated local attacker to exploit an improper pathname limitation. By sending carefully crafted requests to the management service, the attacker could potentially delete arbitrary files, compromising the integrity of configuration settings and leading to a denial of service scenario. This issue fundamentally arises from the mishandling of file paths within the file management functionality, posing significant risks if left unaddressed.
Affected Version(s)
RevPiPyLoad 0 <= 0.11.0
