Junglewise Threat Intelligence

CVE-2026-25069: SunFounder Pironman Dashboard path traversal in log API

CVE-2026-25069 · Severity: info · CVSS 9.3 · Published 2026-02-01

Executive brief

The SunFounder Pironman Dashboard, a management interface for Raspberry Pi hardware cases, contains a security flaw that allows unauthorized users to access or delete files on the system. By sending specially crafted requests, an attacker could steal sensitive information or disable the device by deleting critical system files. This could lead to a total loss of data or a complete service outage for the affected hardware.

Technical details

A path traversal vulnerability (CWE-22) exists in the log file API endpoints of the SunFounder Pironman Dashboard (pm_dashboard) through version 1.3.13. The root cause is a failure to sanitize the 'filename' parameter in the /api/v1.0/get-log and /api/v1.0/delete-log-file endpoints. An unauthenticated remote attacker can use '../' sequences to escape the intended log directory. This allows for arbitrary file read (e.g., accessing /etc/shadow) and arbitrary file deletion across the underlying filesystem. Successful exploitation can lead to sensitive data disclosure, system instability, or a permanent denial of service.

Affected products

  • SunFounder Pironman Dashboard (pm_dashboard) <= 1.3.13

Timeline

  • 2026-01-31: disclosed: Initial disclosure by VulnCheck and chapochapo
  • 2026-02-01: advisory: NVD publication date

References