KUNBUS vulnerabilities
6 CVEs tracked
KUNBUS appears in recent reports with a cluster of critical vulnerabilities across its Revolution Pi industrial controller software stack. Key themes include privileged local exploitation vectors such as an Out-of-bounds Write (CVE-2026-13196) and two Race Conditions (CVE-2026-13197, CVE-2026-13198) in the piControl kernel module, alongside a remotely exploitable unauthenticated CSRF (CVE-2026-57469) in the PiCtory web interface. Defenders should prioritize network isolation for these devices, apply patches for piControl (v2.6.2), PiCtory (v2.16.0), and RevPiPyLoad (v0.11.0) to disrupt potential exploit chains, and enforce strict local access controls.
Azərbaycanca: KUNBUS son hesabatlarda Revolution Pi sənaye kontrollerlərinin proqram təminatındakı bir sıra kritik zəifliklərlə diqqət çəkir. Əsas mövzular bunlardır: piControl nüvə modulunda imtiyazlı yerli hücumçu tərəfindən istismar edilə bilən Out-of-bounds Write (CVE-2026-13196) və iki Race Condition (CVE-2026-13197, CVE-2026-13198) zəifliyi, həmçinin PiCtory veb interfeysində autentikasiya olunmamış uzaqdan hücuma imkan verən CSRF (CVE-2026-57469) problemi. Müdafiəçilər bu sistemləri şəbəkə üzərindən təcrid etməli, istismar zəncirinin qarşısını almaq üçün xüsusilə piControl (v2.6.2), PiCtory (v2.16.0) və RevPiPyLoad (v0.11.0) komponentlərini ən son versiyalara yeniləməli və yerli giriş nəzarətlərini gücləndirməlidir.
This vendor's CVEs6
This hub is built from skopnix's own reporting on KUNBUS: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.