CVE-2025-35996 CRITICAL

CVE-2025-35996: KUNBUS Revolution Pi Improper Neutralization of Server-Side Includes (SSI) Within a Web Page

Vendor Kunbus Gmbh
Product Revolution Pi PiCtory
Weakness CWE-97
Published May 1, 2025
Last update May 2, 2025

CVSS base score

9.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.

Key dates

02Disclosure timeline

May 1, 2025 CVE published
May 2, 2025 Record updated