Unrated severityNVD Advisory· Published Aug 26, 2025· Updated Oct 22, 2025
CVE-2025-25732
CVE-2025-25732
Description
Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.
Affected products
3- Kapsch TrafficCom/RIS-9160 & RIS-9260 Roadside Units (RSUs)description
- Range: v3.2.0.829.23, v3.8.0.1119.42, v4.6.0.1211.28
- Range: v3.2.0.829.23, v3.8.0.1119.42, v4.6.0.1211.28
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- cwe.mitre.org/data/definitions/922.htmlmitre
- phrack.org/issues/72/16_mdmitre
- www.kapsch.net/_Resources/Persistent/3d251a8445e0bf50093903ad70b3dbed34dec7e7/KTC-CVS_RIS-9260_DataSheet.pdfmitre
- www.kapsch.net/_Resources/Persistent/55fb8d0fb279262809eac88d457894db1b3efcd5/Kapsch_RIS-9160_Datasheet_EN.pdfmitre
- www.kapsch.net/enmitre
- www.kapsch.net/en/press/releases/ktc-20200813-pr-enmitre
News mentions
0No linked articles in our index yet.