CVE-2025-25734

EUVD-2025-25798
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
kapschris-9160_firmware
3.2.0.829.23
kapschris-9160_firmware
3.8.0.1119.42
kapschris-9160_firmware
4.6.0.1211.28
kapschris-9260_firmware
3.2.0.829.23
kapschris-9260_firmware
3.8.0.1119.42
kapschris-9260_firmware
4.6.0.1211.28
𝑥
= Vulnerable software versions