ZeroHour

CVE-2025-25732

PoC
CVSS 3.1
6.8 medium
EPSS
<1%p29
Published
()
Modified
Description

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password hashes stored in the EEPROM with hashes of their own, leading to the escalation of privileges to root.

Vendors
kapsch
Products
ris-9160 firmware, ris-9260 firmware
Weakness
CWE-922
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.