CVE-2025-24522
KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.77%
- CWE
- CWE-305
- Published
- 2025-05-01
- Last modified
- 2026-03-12
Affected products
- KUNBUS GmbH Revolution Pi OS Bookworm
Weakness type
Related vulnerabilities
- CVE-2026-86207 — Authentication bypass leads to unauthorised access to N-central
- CVE-2026-81578 — PaperCut MF/NG: Authentication Bypass
- CVE-2026-16895 — Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-53561 — Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user
- CVE-2025-14600 — Admin Account Takeover via Path Traversal in vsDesk
- CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends
- CVE-2026-1621 — Register Bypass in Universal Sotware's E-Municipality