9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.
Basic Information
ID
CVE-2025-25734
Source
mitre
Published
Aug 26, 2025 at 00:00
Modified
Aug 27, 2025 at 14:10
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
References
- www.kapsch.net /en
- www.kapsch.net /_Resources/Persistent/3d251a8445e0bf50093903ad70b3dbed34dec7e7/KTC-CVS_RIS-9260_DataSheet.pdf
- www.kapsch.net /_Resources/Persistent/55fb8d0fb279262809eac88d457894db1b3efcd5/Kapsch_RIS-9160_Datasheet_EN.pdf
- www.kapsch.net /en/press/releases/ktc-20200813-pr-en
- cwe.mitre.org /data/definitions/1233.html
- phrack.org /issues/72/16_md