Unrated severityNVD Advisory· Published Aug 26, 2025· Updated Oct 22, 2025
CVE-2025-25735
CVE-2025-25735
Description
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software running on the system to modify SPI flash in real-time.
Affected products
3- Kapsch TrafficCom/RIS-9160 & RIS-9260 Roadside Units (RSUs)description
- Range: = v3.2.0.829.23, v3.8.0.1119.42, v4.6.0.1211.28
- Range: = v3.2.0.829.23, v3.8.0.1119.42, v4.6.0.1211.28
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- cwe.mitre.org/data/definitions/1233.htmlmitre
- phrack.org/issues/72/16_mdmitre
- www.kapsch.net/_Resources/Persistent/3d251a8445e0bf50093903ad70b3dbed34dec7e7/KTC-CVS_RIS-9260_DataSheet.pdfmitre
- www.kapsch.net/_Resources/Persistent/55fb8d0fb279262809eac88d457894db1b3efcd5/Kapsch_RIS-9160_Datasheet_EN.pdfmitre
- www.kapsch.net/enmitre
- www.kapsch.net/en/press/releases/ktc-20200813-pr-enmitre
News mentions
0No linked articles in our index yet.