CVE-2025-25733: Kapsch Ris-9160 Firmware
Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers to arbitrarily modify SPI flash regions, leading to a degradation of the security posture of the device.
Affected products
- Kapsch Ris-9160 Firmware: version 3.2.0.829.23 only; version 3.8.0.1119.42 only; version 4.6.0.1211.28 only
- Kapsch Ris-9260 Firmware: version 3.2.0.829.23 only; version 3.8.0.1119.42 only; version 4.6.0.1211.28 only
Published 2025-08-26. Last modified 2026-06-17.