Description

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.

INFO

Published Date :

2025-08-26T00:00:00.000Z

Last Modified :

2025-10-22T14:58:01.209Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-25734 vulnerability.

Vendors Products
Kapsch
  • Ris-9160
  • Ris-9160 Firmware
  • Ris-9260
  • Ris-9260 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact