Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.
History

Thu, 18 Sep 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kapsch ris-9160 Firmware
Kapsch ris-9260 Firmware
CPEs cpe:2.3:h:kapsch:ris-9160:-:*:*:*:*:*:*:*
cpe:2.3:h:kapsch:ris-9260:-:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9160_firmware:3.2.0.829.23:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9160_firmware:3.8.0.1119.42:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9160_firmware:4.6.0.1211.28:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9260_firmware:3.2.0.829.23:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9260_firmware:3.8.0.1119.42:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9260_firmware:4.6.0.1211.28:*:*:*:*:*:*:*
Vendors & Products Kapsch ris-9160 Firmware
Kapsch ris-9260 Firmware

Wed, 27 Aug 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kapsch
Kapsch ris-9160
Kapsch ris-9260
Vendors & Products Kapsch
Kapsch ris-9160
Kapsch ris-9260

Tue, 26 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 Aug 2025 15:00:00 +0000

Type Values Removed Values Added
Description Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-26T00:00:00.000Z

Updated: 2025-08-26T16:09:57.688Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25733

cve-icon Vulnrichment

Updated: 2025-08-26T16:09:52.495Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-26T15:15:42.270

Modified: 2025-09-18T15:31:39.373

Link: CVE-2025-25733

cve-icon Redhat

No data.