CVE-2025-24522: KUNBUS Revolution Pi Authentication Bypass by Primary Weakness
KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24522?
CVE-2025-24522 is considered a critical vulnerability due to the lack of default authentication for the Node-RED server.
How do I fix CVE-2025-24522?
To fix CVE-2025-24522, you should configure authentication for the Node-RED server to prevent unauthorized access.
Who is affected by CVE-2025-24522?
CVE-2025-24522 affects users of KUNBUS Revolution Pi OS Bookworm 01/2025 that utilize the Node-RED server.
What impact does CVE-2025-24522 have on systems?
CVE-2025-24522 allows unauthenticated remote attackers to gain full access to the Node-RED server, enabling them to run arbitrary commands.
Is there a patch available for CVE-2025-24522?
As of now, there is no specific patch mentioned for CVE-2025-24522, but implementing authentication will mitigate the risk.