CVE-2025-25735

7.5

Kapsch TrafficCom · RIS-9160 and RIS-9260 Roadside Units (RSUs)

Kapsch TrafficCom RIS-9160 and RIS-9260 Roadside Units lack SPI Protected Range Registers, allowing local software to modify SPI flash memory.

Executive summary

A lack of hardware-level protection in Kapsch TrafficCom RIS-9160 and RIS-9260 units permits unauthorized modification of SPI flash memory, posing a significant risk to device integrity.

Vulnerability

The devices lack SPI Protected Range Registers (PRRs), which allows attackers who have already achieved software execution on the system to perform unauthorized, real-time modifications to the SPI flash memory. This is a local hardware-level vulnerability that requires prior access to the system environment.

Business impact

Successful exploitation allows an attacker to persist in the system or modify critical firmware settings, potentially leading to a complete compromise of the affected Roadside Unit. Given the CVSS score of 7.5, this vulnerability represents a high risk to operational continuity and infrastructure security, as these units are often deployed in sensitive traffic management environments.

Remediation

Immediate Action: Consult the vendor for firmware updates that implement SPI protection or specific configuration hardening guidelines.

Proactive Monitoring: Monitor device access logs for unauthorized software execution or unusual modifications to system configurations.

Compensating Controls: Restrict physical and logical access to the units to prevent unauthorized software from running in the environment, as the vulnerability requires existing software execution to be triggered.

Exploitation status

Public Exploit Available: No (exploit_available unknown).

Analyst recommendation

Due to the nature of this vulnerability, immediate coordination with Kapsch TrafficCom is required to determine the availability of a firmware patch. Until a permanent hardware or software fix is applied, administrators must prioritize hardening the environment to prevent any unauthorized software from executing on the affected units.

More Kapsch TrafficCom CVEs

Sources