Home

Description

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software running on the system to modify SPI flash in real-time.

PUBLISHED Reserved 2025-02-07 | Published 2025-08-26 | Updated 2025-08-27 | Assigner mitre

References

www.kapsch.net/en

www.kapsch.net/...bed34dec7e7/KTC-CVS_RIS-9260_DataSheet.pdf

www.kapsch.net/...b1b3efcd5/Kapsch_RIS-9160_Datasheet_EN.pdf

www.kapsch.net/en/press/releases/ktc-20200813-pr-en

cwe.mitre.org/data/definitions/1233.html

phrack.org/issues/72/16_md

cve.org (CVE-2025-25735)

nvd.nist.gov (CVE-2025-25735)

Download JSON