Home

Description

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.

PUBLISHED Reserved 2025-02-07 | Published 2025-08-26 | Updated 2025-08-26 | Assigner mitre

References

cwe.mitre.org/data/definitions/922.html

www.kapsch.net/en

www.kapsch.net/...bed34dec7e7/KTC-CVS_RIS-9260_DataSheet.pdf

www.kapsch.net/...b1b3efcd5/Kapsch_RIS-9160_Datasheet_EN.pdf

www.kapsch.net/en/press/releases/ktc-20200813-pr-en

phrack.org/issues/72/16_md

cve.org (CVE-2025-25732)

nvd.nist.gov (CVE-2025-25732)

Download JSON