Impact
A Cross‑Site Request Forgery vulnerability (CWE‑352) exists in the web‑based configuration backend of KUNBUS PiCtory version 2.16.0. An attacker who does not have valid credentials can cause a victim’s browser to submit crafted requests that execute state‑changing operations on behalf of an authenticated operator. The attacker could delete project and configuration files or reset the control runtime, compromising data integrity and system availability.
Affected Systems
KUNBUS PiCtory, version 2.16.0
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a victim to be logged in and to allow the attacker’s browser to submit requests, typically through a malicious link or embedded resource. The attack vector is inferred to be a browser‑based CSRF scenario, with no prerequisite that the attacker gain network access to the device.
OpenCVE Enrichment