PT-2025-18691 · Kunbus+1 · Kunbus Revolution Pi Os+1

Adam Bromiley

·

Published

2025-05-01

·

Updated

2025-05-04

·

CVE-2025-24522

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KUNBUS Revolution Pi OS Bookworm 01/2025
Description The issue arises because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server, where they can run arbitrary commands on the underlying operating system.
Recommendations For KUNBUS Revolution Pi OS Bookworm 01/2025, configure authentication for the Node-RED server to prevent unauthenticated access.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-24522

Affected Products

Kunbus Revolution Pi Os
Node-Red