KUNBUS PiCtory是KUNBUS公司的一款工业控制配置软件。 KUNBUS PiCtory 2.16.0及之前版本存在跨站请求伪造漏洞,该漏洞源于Web-based配置后端存在跨站请求伪造,可能导致远程未认证攻击者通过诱导受害者浏览器提交特制请求,在已认证操作员上下文中执行状态更改操作,包括删除项目和配置文件以及重置控制运行时。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13196 | 7.3 HIGH | Out-of-bounds Write in KUNBUS piControl |
| CVE-2026-13197 | 7.3 HIGH | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
| CVE-2026-57472 | 6.9 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS R |
| CVE-2026-57471 | 6.8 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in KUNBUS R |
| CVE-2026-13198 | 5.9 MEDIUM | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet