Skip to main content Skip to page footer

27.07.2026

Kunbus-2026-0000009: Multiple Vulnerabilities in KUNBUS Packages for Revolution Pi

TLP: WHITE

Publisher: KUNBUS PSIRT Document category: csaf_security_advisory
Initial release date: 2026-07-27T14:39:00.926463392Z Engine: csaf-cms-backend 1.0.0-kunbus.1
Current release date: 2026-07-27T14:39:00.926463392Z Build Date: 2026-07-27T14:31:23.202Z
Current version: 1.0.0 Status: final
CVSSv3.1 Base Score: 7.1 Severity:
Original language: Language: en-US
Also referred to:

Vulnerabilities

CSRF in Pictory (CVE-2026-57469)

Description

The pictory web config tool has a CSRF vulnerability that could enable a attacker to take over a session and perform actions on behalf of the logged in user.

CWE: CWE-352:Cross-Site Request Forgery (CSRF)

Product status

Known affected
Product CVSS-Vector CVSS Base Score
KUNBUS Pictory vers:deb/<=2.16.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L 5.4
Fixed
  • KUNBUS Pictory 2.17.0

Remediations

Vendor fix (2026-07-13T10:00:00.000Z)

Update to Pictory Version 1.17.0

For products:
  • KUNBUS Pictory vers:deb/<=2.16.0

References

Possible Extraction of files with the rights of the default user in revpipyload (CVE-2026-57471)

Describtion

An attacker that can access revpipyload XML-RPC interface can gain access to all files the revpipyload process has access to due to improper path checks for the download endpoint.

CWE: CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Known affected
Product CVSS-Vector CVSS Base Score
KUNBUS revpipyload vers:deb/<= 0.11.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 5.5
Fixed
  • KUNBUS revpipyload 0.11.1

Remediations

Vendor fix (2026-07-13T10:00:00.000Z)

Update to revpipyload 0.11.1

For products:
  • KUNBUS revpipyload vers:deb/<= 0.11.0

References

Possible Deletion of files with the rights of default user for a locally authenticated attacker (CVE-2026-57472)

Description

An attacker with access to the revpipyload XML-RPC interface can delete all files the revpipyload process has access rights.

CWE: CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Known affected
Product CVSS-Vector CVSS Base Score
KUNBUS revpipyload vers:deb/<= 0.11.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H 7.1
Fixed
  • KUNBUS revpipyload 0.11.1

Remediations

Vendor fix (2026-07-13T10:00:00.000Z)

Update to revpipyload 0.11.1

For products:
  • KUNBUS revpipyload vers:deb/<= 0.11.0

References

Acknowledgments

KUNBUS PSIRT thanks the following parties for their efforts:
  • Gabriele Quagliarella from Nozomi Networks

KUNBUS PSIRT

Namespace: https://www.kunbus.com

product-security@kunbus.com

KUNBUS GmbH develops and produces the Revolution Pi Family, Revolution Pi OS and the extension modules for RevPi amongst others. KUNBUS PSIRT is responsible for vulnerability handling across all KUNBUS products and services.

References

Revision history

Version Date of the revision Summary of the revision
1.0.0 2026-07-27T14:39:00.926463392Z Initial Publication

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/

Legal Disclaimer

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. KUNBUS RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Kontakt