CVE-2025-25737: Kapsch Ris-9160 Firmware
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.
Affected products
- Kapsch Ris-9160 Firmware: version 3.2.0.829.23 only; version 3.8.0.1119.42 only; version 4.6.0.1211.28 only
- Kapsch Ris-9260 Firmware: version 3.2.0.829.23 only; version 3.8.0.1119.42 only; version 4.6.0.1211.28 only
Published 2025-08-26. Last modified 2026-06-17.