PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-35996 KUNBUS GmbH CVE debrief

CVE-2025-35996 is a critical cross-site scripting issue in KUNBUS PiCtory 2.11.1 and earlier. An authenticated remote attacker can supply a specially crafted filename through API endpoints; when that filename is later shown in the list of configuration files, missing escaping or sanitization can cause the browser to execute it as HTML/script content.

Vendor
KUNBUS GmbH
Product
Revolution Pi OS Bookworm
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2025-05-01
Original CVE updated
2025-07-10
Advisory published
2025-05-01
Advisory updated
2025-07-10

Who should care

Organizations running KUNBUS Revolution Pi / PiCtory, especially operators exposing management or configuration interfaces to authenticated users. This is most relevant where browser-based administration is used and where user-controlled filenames can be stored and later displayed.

Technical summary

The CISA CSAF advisory for ICSA-25-121-01 states that KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a stored cross-site scripting condition. The issue requires an authenticated remote attacker, low privileges, and user interaction, consistent with the CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H. The flaw arises because a crafted filename stored via API endpoints is later transmitted to the client without adequate escaping or sanitization, allowing script execution in the browser context.

Defensive priority

Immediate

Recommended defensive actions

  • Upgrade PiCtory to version 2.12 as recommended by KUNBUS.
  • Use the Cockpit management UI for the preferred update path where available.
  • Enable authentication if it is not already active, following the vendor remediation guidance.
  • Review any workflows that let users create or store filenames that are later displayed in the browser.
  • Apply CISA and vendor guidance to reduce exposure in industrial control system administration interfaces.

Evidence notes

The supplied CISA CSAF source (ICSA-25-121-01) identifies affected product KUNBUS Revolution Pi PiCtory: <=2.11.1 and describes an authenticated remote XSS caused by a crafted filename being stored by API endpoints and later rendered without proper escaping. The same advisory lists remediation to update PiCtory to 2.12, recommends activating authentication, and notes that Update A added a new image release for Revolution Pi OS Bookworm in the mitigations. The CVSS vector provided in the source is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-35996 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-35996

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-35996 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-35996

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-121-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.