CVE-2025-41646

Published Jun 6, 2025

Last updated 25 days ago

CVSS critical 9.8
RevPi Webstatus

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-41646 is a vulnerability in the RevPi Webstatus application. It stems from an incorrect type conversion, which can be exploited by an unauthorized remote attacker to bypass authentication. This could lead to a complete compromise of the affected device. Specifically, the vulnerability allows a remote attacker to bypass authentication. Successful exploitation could grant the attacker full control of the device, potentially allowing them to access, modify, or delete sensitive information, and disrupt device operations. A patch is available from Kunbus, released on June 10, 2025.

Description
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
Source
info@cert.vde.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

info@cert.vde.com
CWE-704

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

23

Configurations