CVE-2026-57471
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS RevPiPyLoad
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to read arbitrary files with the privileges of the RevPiPyLoad daemon, including sensitive configuration and credential material, by sending crafted requests to the local management service.
| CWE | CWE-22 |
| Vendor | kunbus |
| Product | revpipyload |
| Published | Aug 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for kunbus revpipyload
Be the first to know when new unknown vulnerabilities affecting kunbus revpipyload are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
KUNBUS / RevPiPyLoad
0 โค 0.11.0
References
Credits
Gabriele Quagliarella at Nozomi Networks