27.07.2026
Kunbus-2026-0000009: Multiple Vulnerabilities in KUNBUS Packages for Revolution Pi
TLP: WHITE
| Publisher: KUNBUS PSIRT | Document category: csaf_security_advisory |
| Initial release date: 2026-07-27T14:39:00.926463392Z | Engine: csaf-cms-backend 1.0.0-kunbus.1 |
| Current release date: 2026-07-27T14:39:00.926463392Z | Build Date: 2026-07-27T14:31:23.202Z |
| Current version: 1.0.0 | Status: final |
| CVSSv3.1 Base Score: 7.1 | Severity: |
| Original language: | Language: en-US |
| Also referred to: | |
Vulnerabilities
CSRF in Pictory (CVE-2026-57469)
DescriptionThe pictory web config tool has a CSRF vulnerability that could enable a attacker to take over a session and perform actions on behalf of the logged in user.
| CWE: | CWE-352:Cross-Site Request Forgery (CSRF) |
|---|
Product status
Known affected
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS Pictory vers:deb/<=2.16.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L | 5.4 |
Fixed
- KUNBUS Pictory 2.17.0
Remediations
Vendor fix (2026-07-13T10:00:00.000Z)
Update to Pictory Version 1.17.0
For products:
- KUNBUS Pictory vers:deb/<=2.16.0
References
- Nozomi Networks security advisory NN-2026-123 (external) https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57469
Possible Extraction of files with the rights of the default user in revpipyload (CVE-2026-57471)
DescribtionAn attacker that can access revpipyload XML-RPC interface can gain access to all files the revpipyload process has access to due to improper path checks for the download endpoint.
| CWE: | CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
|---|
Product status
Known affected
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS revpipyload vers:deb/<= 0.11.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 5.5 |
Fixed
- KUNBUS revpipyload 0.11.1
Remediations
Vendor fix (2026-07-13T10:00:00.000Z)
Update to revpipyload 0.11.1
For products:
- KUNBUS revpipyload vers:deb/<= 0.11.0
References
- Nozomi Networks security advisory NN-2026-0125 (external) https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57471
Possible Deletion of files with the rights of default user for a locally authenticated attacker (CVE-2026-57472)
DescriptionAn attacker with access to the revpipyload XML-RPC interface can delete all files the revpipyload process has access rights.
| CWE: | CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
|---|
Product status
Known affected
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS revpipyload vers:deb/<= 0.11.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H | 7.1 |
Fixed
- KUNBUS revpipyload 0.11.1
Remediations
Vendor fix (2026-07-13T10:00:00.000Z)
Update to revpipyload 0.11.1
For products:
- KUNBUS revpipyload vers:deb/<= 0.11.0
References
- Nozomi Networks security advisory NN-2026-0126 (external) https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-57472
Acknowledgments
KUNBUS PSIRT thanks the following parties for their efforts:- Gabriele Quagliarella from Nozomi Networks
KUNBUS PSIRT
Namespace: https://www.kunbus.com
product-security@kunbus.com
KUNBUS GmbH develops and produces the Revolution Pi Family, Revolution Pi OS and the extension modules for RevPi amongst others. KUNBUS PSIRT is responsible for vulnerability handling across all KUNBUS products and services.
References
- URL generated by system (self) https://psirt.kunbus.com/white/2026/kunbus-2026-0000009.json
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1.0.0 | 2026-07-27T14:39:00.926463392Z | Initial Publication |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/
Legal Disclaimer
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. KUNBUS RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.