216.73.217.22

CVE-2025-25736

· Published 26/08/2025 15:15 · Modified 27/08/2025 14:15

Labels: CVE-2025-25736 2025-08-26CVE-2025-25736CWE-306[email protected]

Essential information

Published
26/08/2025 15:15
Modified
27/08/2025 14:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated root shell access to the cellular modem via the default 'kapsch' user.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
kapsch / trafficcom ris-9260 rsu leo cpe:2.3:a:kapsch:trafficcom_ris-9260_rsu_leo:3.2.0.829.23:*:*:*:*:*:*:*
kapsch / trafficcom ris-9260 rsu leo cpe:2.3:a:kapsch:trafficcom_ris-9260_rsu_leo:3.8.0.1119.42:*:*:*:*:*:*:*
kapsch / trafficcom ris-9260 rsu leo cpe:2.3:a:kapsch:trafficcom_ris-9260_rsu_leo:4.6.0.1211.28:*:*:*:*:*:*:*

References