TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-25736

MEDIUM
6.8

Description

Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated root shell access to the cellular modem via the default 'kapsch' user.

Details CVE

Score CVSS v3.16.8
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaquePHYSICAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie8/26/2025
Derniere modification10/22/2025
Sourcenvd
Observations honeypot0

Produits affectes

kapsch:ris-9160kapsch:ris-9160_firmwarekapsch:ris-9260kapsch:ris-9260_firmware

Faiblesses (CWE)

CWE-306

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.