Vulnerability record · CVE-2025-41646 · published 6 June 2025
CVE-2025-41646: Kunbus Revolution Pi revpi_status authentication bypass via type conversion
Kunbus · Revpi Status
Kunbus revpi_status contains an authentication bypass caused by misuse of an incorrect type conversion (CWE-704). An unauthenticated remote attacker can exploit this to bypass authentication and gain full control of the affected device.
Description
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and full device compromise, plus a very high EPSS score, makes this an urgent fix despite no confirmed in-the-wild exploitation.
What it is
Kunbus revpi_status contains an authentication bypass caused by misuse of an incorrect type conversion (CWE-704). An unauthenticated remote attacker can exploit this to bypass authentication and gain full control of the affected device.
Impact
An attacker gains complete compromise of the device, with high impact to confidentiality, integrity and availability. This can expose or alter device data and disrupt the industrial process the device controls.
Attack surface
The flaw is reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any network-reachable instance of revpi_status is potentially exposed.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.51548 (98.9th percentile), indicating a high modeled likelihood of exploitation.
What to do
- Apply the vendor fix from the Kunbus advisory (Kunbus-2025-0000003) as soon as it is available.
- Restrict network access to revpi_status to trusted management hosts using firewall rules or network segmentation.
- Do not expose the service to untrusted networks or the internet.
- Monitor vendor channels for updated firmware or package releases and redeploy promptly.
- If patching is delayed, consider disabling or isolating the affected service where operationally feasible.
Detection
- Monitor authentication and access logs for revpi_status for successful sessions that lack a preceding valid login.
- Alert on unexpected or anomalous network connections to the revpi_status service from untrusted hosts.
- Watch for configuration changes, reboots or process restarts on Revolution Pi devices that are not tied to known maintenance.
- Baseline normal client IPs and flag new source addresses reaching the service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-41646 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2025-41646), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.