PatchSiren cyber security CVE debrief
CVE-2025-41646 KUNBUS CVE debrief
CVE-2025-41646 affects KUNBUS Revolution Pi Webstatus and is rated Critical (CVSS 9.8). CISA’s CSAF advisory says the password check can be bypassed because of implicit type conversion, allowing incorrect authentication when the JSON value TRUE is supplied in the password parameter hashcode. KUNBUS provides a fixed Webstatus package version 2.4.6. The advisory also lists several Revolution Pi OS Bullseye releases in the affected set. No KEV entry is listed in the supplied data.
- Vendor
- KUNBUS
- Product
- Revolution Pi Webstatus
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-10
- Original CVE updated
- 2025-07-10
- Advisory published
- 2025-07-10
- Advisory updated
- 2025-07-10
Who should care
KUNBUS Revolution Pi operators, OT/ICS administrators, plant engineers, and incident responders responsible for Revolution Pi Webstatus installations or Revolution Pi OS Bullseye systems listed in the advisory.
Technical summary
The advisory describes an authentication bypass in the Webstatus application’s password validation path. A JSON TRUE value in the password parameter hashcode can trigger implicit type conversion and lead to an incorrect authentication outcome. The vulnerable Webstatus release is <= 2.4.5; KUNBUS identifies Webstatus 2.4.6 as the updated package. The CSAF advisory enumerates additional Revolution Pi OS Bullseye build entries as affected products.
Defensive priority
Critical. The supplied CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely reachable, unauthenticated issue with high confidentiality, integrity, and availability impact.
Recommended defensive actions
- Prioritize upgrading Revolution Pi Webstatus to version 2.4.6 using the vendor package or apt-get update && apt-get upgrade, as directed by KUNBUS.
- If immediate upgrading is not possible, follow the workarounds and mitigations in the CISA/KUNBUS advisory for all affected product entries.
- Inventory all Revolution Pi Webstatus deployments and compare against the affected version range (<= 2.4.5).
- Validate whether any Revolution Pi OS Bullseye installations listed in the advisory bundle Webstatus and should be included in remediation planning.
- Confirm post-change authentication behavior and monitor for unexpected authentication attempts against Webstatus.
Evidence notes
Based on CISA CSAF ICSA-25-191-09 and the supplied advisory metadata, CVE-2025-41646 was initially published on 2025-07-10 and describes an authentication bypass in KUNBUS Revolution Pi Webstatus caused by implicit type conversion when JSON TRUE is supplied in the password parameter hashcode. The affected Webstatus range is <= 2.4.5, with vendor fix 2.4.6. Supplied enrichment marks the issue as not listed in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-41646 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-41646
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-41646 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-41646
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-191-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.