KUNBUS Revolution Pi Path Traversal Vulnerability
Vulnerability
A path traversal vulnerability exists in KUNBUS Revolution Pi version 2022-07-28-revpi-buster. This vulnerability allows an authenticated attacker to list device directories through the '/pictory/php/getFileList.php' endpoint by manipulating the 'dir' parameter.
Impact
Exploitation of this vulnerability could lead to unauthorized directory listing, allowing attackers to view sensitive file structures on the device.
Remediation
KUNBUS has released a patch for this vulnerability in Revolution Pi pictory version 2.1.1.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.0exploitability
5.2remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
