PatchSiren cyber security CVE debrief
CVE-2025-36558 KUNBUS GmbH CVE debrief
CVE-2025-36558 is a reflected cross-site scripting vulnerability in KUNBUS PiCtory version 2.11.1 and earlier. According to the CISA CSAF advisory, an attacker can supply a PiCtory URL with HTML/script content in the sso_token used for authentication, causing the script to be returned to the user and executed. The advisory rates the issue CVSS 6.1 (medium) and lists PiCtory 2.12 as the remediation target.
- Vendor
- KUNBUS GmbH
- Product
- Revolution Pi OS Bookworm
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-01
- Original CVE updated
- 2025-07-10
- Advisory published
- 2025-05-01
- Advisory updated
- 2025-07-10
Who should care
Operators and integrators running KUNBUS PiCtory 2.11.1 or earlier, especially in environments where users may open PiCtory links from emails, tickets, chat, or external systems. Security teams responsible for web application hardening and industrial control system support should also review exposure.
Technical summary
The affected component is KUNBUS PiCtory <= 2.11.1. The weakness is a cross-site scripting condition involving the sso_token authentication parameter. The vulnerable behavior is reflected content handling: if a crafted URL is delivered to a user, script content placed in sso_token can be echoed back and executed in the user’s browser. The CVSS v3.1 vector provided by the source is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability, no privileges required, and user interaction.
Defensive priority
Medium
Recommended defensive actions
- Upgrade PiCtory to version 2.12 as recommended in the CSAF advisory.
- Prefer the KUNBUS Cockpit management UI for the update process, or use the vendor-provided package source referenced in the advisory.
- Enable authentication where it is not already active, following the KUNBUS remediation guidance.
- Review links and workflows that distribute PiCtory URLs to users, and treat untrusted sso_token values as suspicious.
- Re-check the advisory after the 2025-07-10 Update A, which added a new Revolution Pi OS Bookworm image release to the mitigations.
Evidence notes
All core claims are taken from the CISA CSAF advisory ICSA-25-121-01 and its included notes/references: PiCtory 2.11.1 and earlier are affected; the issue is cross-site scripting via sso_token; and version 2.12 is the stated update target. The advisory revision history shows the initial publication on 2025-05-01 and Update A on 2025-07-10, which added a new image release to mitigations. CVSS and vector details are taken from the advisory metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36558 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36558
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36558 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36558
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-121-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.