CVE-2025-24522 Details
Description
KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.
A vulnerability exists in KUNBUS Revolution Pi OS Bookworm 01/2025 and earlier, as well as in Revolution Pi PiCtory versions 2.5.0 through 2.11.1. The issue arises because authentication is not enabled by default for the Node-RED server. This lack of authentication allows unauthenticated remote attackers to gain full access to the Node-RED server and execute arbitrary commands on the underlying operating system.
Users are advised to update the PiCtory package to version 2.12. The update can be downloaded from the KUNBUS Revolution Pi package repository. After updating, it is recommended to activate authentication on the Node-RED server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2025CISA-ADP
Assessed May 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://packages.revolutionpi.de/pool/main/p/pictory/ | [email protected] | Source CodeVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-305 | Authentication Bypass by Primary Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KUNBUS Revolution Pi OS Bookworm | All versions |
CPE
Remediation
| |
| KUNBUS Revolution Pi PiCtory | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2025 | New CVE Received | [email protected] |
Volerion