← Back

CVE-2025-25733

nvd nist
Published: Aug 26, 2025Modified: Jun 17, 2026

JSON object

Loading...
3.5
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 0.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.

Affected (6)

2 products
Ris 9160 Firmware
Ris 9260 Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Kapsch
Version 3.2.0.829.23
Version 3.8.0.1119.42
Version 4.6.0.1211.28
Running on/withPlatform Versions
Kapsch
Ris 9160
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Kapsch
Version 3.2.0.829.23
Version 3.8.0.1119.42
Version 4.6.0.1211.28
Running on/withPlatform Versions
Kapsch
Ris 9260
All versions

Timeline

No history available yet.