GHSA-6rrq-ffwf-5j3wMedium

Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted...

Published
August 14, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to read arbitrary files with the privileges of the RevPiPyLoad daemon, including sensitive configuration and credential material, by sending crafted requests to the local management service.

🔗 References (3)