← back
CVE-2025-41646criticalobserved exploitationCWE-704

RevPi Webstatus application is vulnerable to an authentication bypass

97Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 44%
from disclosure to weapon28 days
Published on NVDJun 6
1st PoC+28d
VulnCheck+45d
exploitation probability
44%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.