7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software running on the system to modify SPI flash in real-time.
Basic Information
ID
CVE-2025-25735
Source
mitre
Published
Aug 26, 2025 at 00:00
Modified
Aug 27, 2025 at 14:08
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
References
- www.kapsch.net /en
- www.kapsch.net /_Resources/Persistent/3d251a8445e0bf50093903ad70b3dbed34dec7e7/KTC-CVS_RIS-9260_DataSheet.pdf
- www.kapsch.net /_Resources/Persistent/55fb8d0fb279262809eac88d457894db1b3efcd5/Kapsch_RIS-9160_Datasheet_EN.pdf
- www.kapsch.net /en/press/releases/ktc-20200813-pr-en
- cwe.mitre.org /data/definitions/1233.html
- phrack.org /issues/72/16_md