CISA Alerts on KUNBUS Auth Bypass Flaws Allowing Remote System Exploits

CISA Alerts on KUNBUS Auth Bypass Flaws Allowing Remote System Exploits

Critical Security Flaws Found in KUNBUS Revolution Pi Devices: Immediate Action Urged

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a high-priority alert regarding severe security weaknesses in KUNBUS GmbH’s Revolution Pi line—devices widely used for industrial automation across essential industries.

These vulnerabilities open the door to unauthorized system access and full remote takeover, threatening the continuity and safety of operations in sectors such as energy, manufacturing, transportation, and healthcare.

What’s at Risk?

Three major flaws have been identified in Revolution Pi OS Bookworm (as of January 2025) and the PiCtory software (versions 2.5.0 to 2.11.1), each carrying a CVSS score near or at the maximum:

  1. Unprotected Command Execution (CVE-2025-24522)
    The integrated Node-RED service lacks basic access controls. Without authentication, attackers can run commands directly on the device, potentially taking full control of industrial systems. Severity: CVSS 10.0
  2. Auth Bypass via Directory Traversal (CVE-2025-32011)
    Exploiting a path traversal flaw, attackers can sidestep authentication in PiCtory to manipulate configurations or exfiltrate critical data. Severity: CVSS 9.8
  3. Malicious Script Injection (CVE-2025-24524)
    Poor filename sanitization enables Server-Side Includes (SSI) attacks, allowing bad actors with limited access to inject harmful scripts, hijack sessions, or launch targeted payloads. Severity: CVSS 9.8

Why It Matters

Revolution Pi devices are embedded in infrastructure around the globe—from managing water treatment sensors to regulating factory production lines. These flaws, if exploited, could bring critical processes to a halt or expose operational data to malicious hands.

Though patches have been released by KUNBUS, many installations—especially in tightly controlled environments—may face delays in updating, leaving gaps that threat actors can exploit.

What You Should Do Now

CISA and KUNBUS are calling on all users to act decisively:

  • Upgrade Immediately: Update PiCtory to version 2.12 through the KUNBUS Cockpit interface or download it manually.
  • Enforce Authentication: Activate secure login credentials for both Node-RED and PiCtory.
  • Segment Networks: Physically or logically separate ICS from IT networks using firewalls and VLANs.
  • Lock Down Internet Exposure: Audit network configurations to ensure ICS devices are not accessible from the public web.

KUNBUS also plans to introduce a Cockpit security plugin by April 2025 to help streamline secure configuration.

Discovery and Disclosure

These vulnerabilities were responsibly reported by Adam Bromiley of Pen Test Partners and coordinated with both KUNBUS and CISA. While there are currently no reports of exploitation in the wild, the history of attacks on industrial systems makes proactive defense critical.

A Wake-Up Call for Industrial IoT

These findings highlight the systemic risks within industrial IoT ecosystems. In an era where critical infrastructure is a prime target, organizations must treat device hardening and lifecycle patching as non-negotiable. The cost of inaction could be operational paralysis—or worse.

More Articles & Posts