KUNBUS piControl是KUNBUS公司的一套实时控制软件平台,主要负责设备的硬件管理、实时通信及工业控制功能。 KUNBUS piControl 2.6.2版本存在缓冲区错误漏洞,该漏洞源于进程图像管理功能存在越界写入问题,本地认证攻击者可利用设备配置访问权限,通过piControl字符设备提供特制的设备配置数据和输入,在进程图像缓冲区边界之外写入攻击者控制的数据并破坏相邻内核内存,导致内核内存损坏和拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13197 | 7.3 HIGH | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
| CVE-2026-57472 | 6.9 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS R |
| CVE-2026-57471 | 6.8 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS R |
| CVE-2026-13198 | 5.9 MEDIUM | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
| CVE-2026-57469 | 5.1 MEDIUM | Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory |
No comments yet