216.73.217.22

CVE-2025-25737

· Published 26/08/2025 15:15 · Modified 27/08/2025 15:15

Labels: CVE-2025-25737 2025-08-26CVE-2025-25737CWE-521[email protected]

Essential information

Published
26/08/2025 15:15
Modified
27/08/2025 15:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
kapsch trafficcom / ris-9160 cpe:2.3:a:kapsch_trafficcom:ris-9160:3.2.0.829.23:*:*:*:*:*:*:*
kapsch trafficcom / ris-9160 cpe:2.3:a:kapsch_trafficcom:ris-9160:3.8.0.1119.42:*:*:*:*:*:*:*
kapsch trafficcom / ris-9160 cpe:2.3:a:kapsch_trafficcom:ris-9160:4.6.0.1211.28:*:*:*:*:*:*:*
kapsch trafficcom / ris-9260 cpe:2.3:a:kapsch_trafficcom:ris-9260:3.2.0.829.23:*:*:*:*:*:*:*
kapsch trafficcom / ris-9260 cpe:2.3:a:kapsch_trafficcom:ris-9260:3.8.0.1119.42:*:*:*:*:*:*:*
kapsch trafficcom / ris-9260 cpe:2.3:a:kapsch_trafficcom:ris-9260:4.6.0.1211.28:*:*:*:*:*:*:*

References