KUNBUS piControl是KUNBUS公司的一套实时控制软件平台,主要负责设备的硬件管理、实时通信及工业控制功能。 KUNBUS piControl 2.6.2版本存在竞争条件问题漏洞,该漏洞源于事件通知功能存在竞争条件问题,可能导致本地认证攻击者通过piControl字符设备从多个线程发出并发特制请求,破坏内核堆和事件列表状态,泄露少量相邻内核内存,导致内核内存损坏和拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13196 | 7.3 HIGH | Out-of-bounds Write in KUNBUS piControl |
| CVE-2026-13197 | 7.3 HIGH | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
| CVE-2026-57472 | 6.9 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS R |
| CVE-2026-57471 | 6.8 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS R |
| CVE-2026-57469 | 5.1 MEDIUM | Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory |
No comments yet