Impact
The flaw exists in the XML‑RPC file management functionality of KUNBUS RevPiPyLoad. An attacker with local, unauthenticated access can craft malicious XML‑RPC requests that cause the daemon to resolve file paths outside the intended directory. This allows arbitrary file deletion with the daemon’s privileges, compromising device configuration and potentially bringing the service offline.
Affected Systems
KUNBUS RevPiPyLoad version 0.11.0 is affected. The vulnerability is specific to the file management commands exposed by the XML‑RPC management interface. Devices running earlier or later releases that have not adopted the patch are not vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high risk severity. No EPSS score is currently available, and the flaw is not listed in the CISA KEV catalog, suggesting limited public exploitation data. However, the attack requires only local access and no authentication, meaning an insider or an attacker who has compromised the host can easily delete critical files and disrupt service. The path traversal weakness (CWE‑22) reduces the overall mitigation options, and organizations should treat this as an urgent issue if the affected version is in use.
OpenCVE Enrichment