CVE-2024-8685: Kunbus GmbH Revolution Pi

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter.

Affected products

Published 2025-02-10. Last modified 2026-06-17.