Nozomi Networks vulnerabilities
3 CVEs tracked
In recent reporting, Nozomi Networks Labs is featured as a security research group, primarily presenting analysis on the Mirai-derived Tengu botnet and disclosing several vulnerabilities in KUNBUS products. The Tengu botnet leverages the hardware watchdog on compromised Linux devices to reboot the system when its main process is terminated, reactivating its persistence mechanisms. Concurrently, Nozomi Networks identified vulnerabilities in KUNBUS RevPiPyLoad (CVE-2026-57471, CVE-2026-57472: Path Traversal) and PiCtory (CVE-2026-57469: CSRF). Defenders should consider these reports to counter the Tengu botnet by focusing on eliminating its persistence mechanisms beyond process termination, and for the listed CVEs, update the affected KUNBUS devices in OT/ICS environments with the relevant patches.
Azərbaycanca: Son hesabatlarda Nozomi Networks Labs təhlükəsizlik araşdırma qrupu kimi önə çıxır, əsasən Mirai variantı olan Tengu botneti ilə bağlı təhlil və KUNBUS məhsullarında aşkarlanan bir neçə boşluğu təqdim edir. Tengu botneti Linux cihazlarında hardware watchdog-u istifadə edərək əsas proses dayandırıldıqda sistemi yenidən başladır ki, bu da onun persistence mexanizmlərini aktivləşdirir. Eyni zamanda, Nozomi Networks tərəfindən KUNBUS-un RevPiPyLoad (CVE-2026-57471, CVE-2026-57472: Path Traversal) və PiCtory (CVE-2026-57469: CSRF) məhsullarında zəifliklər müəyyən edilib. Müdafiəçilər bu hesabatları nəzərə alaraq Tengu botnetinə qarşı proses öldürməkdən əlavə persistence mexanizmlərini aradan qaldırmağa diqqət yetirməli, sadalanan CVE-lər üçün isə təsirlənmiş OT/ICS mühitlərində KUNBUS cihazlarını müvafiq patch-lərlə yeniləməlidirlər.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Nozomi Networks: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.