CVE-2025-41646: RevPi Webstatus application is vulnerable to an authentication bypass
Published Jun 6, 2025
·Updated
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
Affected Software
2 affected components
RevPi Webstatus
Kunbus Revpi Status<2.4.6
Event History
Jun 6, 2025
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-41646?
CVE-2025-41646 has been classified with a high severity rating due to the potential for unauthorized remote access.
2
How do I fix CVE-2025-41646?
To fix CVE-2025-41646, update the affected RevPi Webstatus software to the latest version released by Kunbus.
3
What impact does CVE-2025-41646 have on affected systems?
CVE-2025-41646 can lead to full compromise of the device, allowing attackers unauthorized access.
4
Is CVE-2025-41646 being actively exploited?
As of the latest reports, there is evidence suggesting that CVE-2025-41646 may be actively exploited in the wild.
5
Who is affected by CVE-2025-41646?
The vulnerability affects users of the RevPi Webstatus software, which is used in various industrial applications.