Description
KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.
Problem types
Product status
Any version
Credits
Adam Bromiley of Pen Test Partners reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-121-01
packages.revolutionpi.de/pool/main/p/pictory/