PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-41646 KUNBUS CVE debrief

CVE-2025-41646 affects KUNBUS Revolution Pi Webstatus and is rated Critical (CVSS 9.8). CISA’s CSAF advisory says the password check can be bypassed because of implicit type conversion, allowing incorrect authentication when the JSON value TRUE is supplied in the password parameter hashcode. KUNBUS provides a fixed Webstatus package version 2.4.6. The advisory also lists several Revolution Pi OS Bullseye releases in the affected set. No KEV entry is listed in the supplied data.

Vendor
KUNBUS
Product
Revolution Pi Webstatus
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-07-10
Original CVE updated
2025-07-10
Advisory published
2025-07-10
Advisory updated
2025-07-10

Who should care

KUNBUS Revolution Pi operators, OT/ICS administrators, plant engineers, and incident responders responsible for Revolution Pi Webstatus installations or Revolution Pi OS Bullseye systems listed in the advisory.

Technical summary

The advisory describes an authentication bypass in the Webstatus application’s password validation path. A JSON TRUE value in the password parameter hashcode can trigger implicit type conversion and lead to an incorrect authentication outcome. The vulnerable Webstatus release is <= 2.4.5; KUNBUS identifies Webstatus 2.4.6 as the updated package. The CSAF advisory enumerates additional Revolution Pi OS Bullseye build entries as affected products.

Defensive priority

Critical. The supplied CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely reachable, unauthenticated issue with high confidentiality, integrity, and availability impact.

Recommended defensive actions

  • Prioritize upgrading Revolution Pi Webstatus to version 2.4.6 using the vendor package or apt-get update && apt-get upgrade, as directed by KUNBUS.
  • If immediate upgrading is not possible, follow the workarounds and mitigations in the CISA/KUNBUS advisory for all affected product entries.
  • Inventory all Revolution Pi Webstatus deployments and compare against the affected version range (<= 2.4.5).
  • Validate whether any Revolution Pi OS Bullseye installations listed in the advisory bundle Webstatus and should be included in remediation planning.
  • Confirm post-change authentication behavior and monitor for unexpected authentication attempts against Webstatus.

Evidence notes

Based on CISA CSAF ICSA-25-191-09 and the supplied advisory metadata, CVE-2025-41646 was initially published on 2025-07-10 and describes an authentication bypass in KUNBUS Revolution Pi Webstatus caused by implicit type conversion when JSON TRUE is supplied in the password parameter hashcode. The affected Webstatus range is <= 2.4.5, with vendor fix 2.4.6. Supplied enrichment marks the issue as not listed in CISA KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-41646 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-41646

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-41646 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-41646

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-191-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-191-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.