CVE-2025-25737

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.
Configurations

No configuration.

History

27 Aug 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió que Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, y v4.6.0.1211.28 carecían de requisitos de contraseña segura para sus cuentas de supervisor y usuario del BIOS, lo que permitía a los atacantes eludir la autenticación mediante un ataque de fuerza bruta.
References () https://phrack.org/issues/72/16_md - () https://phrack.org/issues/72/16_md -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-521

26 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 15:15

Updated : 2025-08-29 16:22


NVD link : CVE-2025-25737

Mitre link : CVE-2025-25737

CVE.ORG link : CVE-2025-25737


JSON object : View

Products Affected

No product.

CWE
CWE-521

Weak Password Requirements