ID:11814 - Exploit for Incorrect Implementation of Authentication Algorithm in Revolution Pi Webstatus and Revolution Pi OS Bullseye - CVE-2025-41646

 
Main Vulnerability Database Exploits ID:11814 - Exploit for Incorrect Implementation of Authentication Algorithm in Revolution Pi Webstatus and Revolution Pi OS Bullseye - CVE-2025-41646

ID:11814 - Exploit for Incorrect Implementation of Authentication Algorithm in Revolution Pi Webstatus and Revolution Pi OS Bullseye - CVE-2025-41646

Published: August 1, 2025


Vulnerability identifier: #VU112894
Vulnerability risk: High
CVE-ID: CVE-2025-41646
CWE-ID: CWE-303
Exploitation vector: Remote access
Vulnerable software:
Revolution Pi Webstatus
Revolution Pi OS Bullseye

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to implicit type conversion within the password check. A remote attacker can bypass authentication on the target system.


Remediation

Install updates from vendor's website.