Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to delete arbitrary files with the privileges of the RevPiPyLoad daemon, resulting in loss of configuration integrity and denial of service, by sending crafted requests to the local management service.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kunbus
Kunbus revpipyload |
|
| Vendors & Products |
Kunbus
Kunbus revpipyload |
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to delete arbitrary files with the privileges of the RevPiPyLoad daemon, resulting in loss of configuration integrity and denial of service, by sending crafted requests to the local management service. | |
| Title | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Nozomi
Published: 2026-08-14T15:04:47.414Z
Updated: 2026-08-14T19:41:31.232Z
Reserved: 2026-06-24T13:49:50.681Z
Link: CVE-2026-57472
Updated: 2026-08-14T19:41:26.391Z
Status : Awaiting Analysis
Published: 2026-08-14T16:16:58.293
Modified: 2026-08-28T19:46:29.323
Link: CVE-2026-57472
No data.