Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software running on the system to modify SPI flash in real-time.
History

Tue, 16 Sep 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Kapsch ris-9160 Firmware
Kapsch ris-9260 Firmware
CPEs cpe:2.3:h:kapsch:ris-9160:-:*:*:*:*:*:*:*
cpe:2.3:h:kapsch:ris-9260:-:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9160_firmware:3.2.0.829.23:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9160_firmware:3.8.0.1119.42:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9160_firmware:4.6.0.1211.28:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9260_firmware:3.2.0.829.23:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9260_firmware:3.8.0.1119.42:*:*:*:*:*:*:*
cpe:2.3:o:kapsch:ris-9260_firmware:4.6.0.1211.28:*:*:*:*:*:*:*
Vendors & Products Kapsch ris-9160 Firmware
Kapsch ris-9260 Firmware

Wed, 27 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1233
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 27 Aug 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Kapsch
Kapsch ris-9160
Kapsch ris-9260
Vendors & Products Kapsch
Kapsch ris-9160
Kapsch ris-9260

Tue, 26 Aug 2025 15:00:00 +0000

Type Values Removed Values Added
Description Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software running on the system to modify SPI flash in real-time.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-26T00:00:00.000Z

Updated: 2025-08-27T14:08:30.169Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25735

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-08-26T15:15:42.617

Modified: 2025-09-16T19:33:52.560

Link: CVE-2025-25735

cve-icon Redhat

No data.