KUNBUS Revolution Pi Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability exists in KUNBUS Revolution Pi version 2022-07-28-revpi-buster. This vulnerability allows an authenticated attacker to list device directories through the '/pictory/php/getFileList.php' endpoint by manipulating the 'dir' parameter.

Impact

Exploitation of this vulnerability could lead to unauthorized directory listing, allowing attackers to view sensitive file structures on the device.

Remediation

KUNBUS has released a patch for this vulnerability in Revolution Pi pictory version 2.1.1.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.