CVE-2025-25737
MEDIUMDescription
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.
Is your site exposed to CVE-2025-25737?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| kapsch | ris-9160_firmware |
| kapsch | ris-9160_firmware |
| kapsch | ris-9160_firmware |
| kapsch | ris-9160 |
| kapsch | ris-9260_firmware |
| kapsch | ris-9260_firmware |
| kapsch | ris-9260_firmware |
| kapsch | ris-9260 |
References
Exploits
Other References
Frequently Asked Questions
What is CVE-2025-25737? +
How severe is CVE-2025-25737? +
What products are affected by CVE-2025-25737? +
How do I check if I'm vulnerable to CVE-2025-25737? +
Related Vulnerabilities
No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console …
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After …
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through …
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 …
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any …
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of …