CVE-2025-25734
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.
Affected (6)
Products: Kapsch: Ris 9160 Firmware, Ris 9260 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2.0.829.23 |
| Running on/with | Platform Versions |
|---|---|
Kapsch Ris 9160 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2.0.829.23 |
| Running on/with | Platform Versions |
|---|---|
Kapsch Ris 9260 | All versions |
Related CWEs
CWE-1233
Security-Sensitive Hardware Controls with Missing Lock Bit Protection
The product uses a register lock bit protection mechanism, but it does not ensure that the lock bit prevents modification of system registers or controls that perform changes to important hardware system configuration.
CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
References (6)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Product
Timeline
No history available yet.