CVE-2025-41646

CRITICAL EXPLOITED NUCLEI

Software Package - Auth Bypass

Title source: llm

Description

An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device

Exploits (2)

nomisec WORKING POC 1 stars
by GreenForceNetworks · poc
https://github.com/GreenForceNetworks/CVE-2025-41646---Critical-Authentication-Bypass-
nomisec WORKING POC
by r0otk3r · remote
https://github.com/r0otk3r/CVE-2025-41646

Nuclei Templates (1)

RevPi Webstatus <= v2.4.5 - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDK
Shodan: title:"RevPi"

Scores

CVSS v3 9.8
EPSS 0.3384
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-07-21
CWE
CWE-704
Status published
Products (1)
kunbus/revpi_status < 2.4.6
Published Jun 06, 2025
Tracked Since Feb 18, 2026