CVE-2025-25734
Essential information
- Published
- 26/08/2025 15:15
- Modified
- 27/08/2025 15:15
- Author
- —
- Creator
- —
- CVSS
- 9.8 CRITICAL (v3.1)
- CISA KEV
- No
- CWE
- —
- CVSS vector
-
—
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H—
CVSS metrics
- Access vector
- —
- Access complexity
- —
- Authentication
- —
- Confidentiality impact
- —
- Integrity impact
- —
- Availability impact
- —
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- NETWORK
- Attack complexity
- LOW
- Privileges required
- NONE
- User interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality impact
- HIGH
- Integrity impact
- HIGH
- Availability impact
- HIGH
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Attack requirements
- —
- Privileges required
- —
- User interaction
- —
- Confidentiality (V)
- —
- Confidentiality (S)
- —
- Integrity (V)
- —
- Integrity (S)
- —
- Availability (V)
- —
- Availability (S)
- —
- Exploit maturity
- —
Description
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.
NVD status
- Status
- Received — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| kapsch trafficcom / ris-9160 | cpe:2.3:a:kapsch_trafficcom:ris-9160:3.2.0.829.23:*:*:*:*:*:*:* |
| kapsch trafficcom / ris-9160 | cpe:2.3:a:kapsch_trafficcom:ris-9160:3.8.0.1119.42:*:*:*:*:*:*:* |
| kapsch trafficcom / ris-9160 | cpe:2.3:a:kapsch_trafficcom:ris-9160:4.6.0.1211.28:*:*:*:*:*:*:* |
| kapsch trafficcom / ris-9260 | cpe:2.3:a:kapsch_trafficcom:ris-9260:3.2.0.829.23:*:*:*:*:*:*:* |
| kapsch trafficcom / ris-9260 | cpe:2.3:a:kapsch_trafficcom:ris-9260:3.8.0.1119.42:*:*:*:*:*:*:* |
| kapsch trafficcom / ris-9260 | cpe:2.3:a:kapsch_trafficcom:ris-9260:4.6.0.1211.28:*:*:*:*:*:*:* |