CVE-2025-25735
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 0.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software running on the system to modify SPI flash in real-time.
Affected (6)
Products: Kapsch: Ris 9160 Firmware, Ris 9260 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2.0.829.23 |
| Running on/with | Platform Versions |
|---|---|
Kapsch Ris 9160 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.2.0.829.23 |
| Running on/with | Platform Versions |
|---|---|
Kapsch Ris 9260 | All versions |
References (6)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Product
Timeline
No history available yet.