CVE Explorer
CVE-2025-8699
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure MiFare Classic NFC card and can be read and written back. By carefully observing changes in card dumps, one can identify fields that store the cash value of the card. Additionally, a checksum can be identified, which is created by XOR-ing the cash and an unknown
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Stored Value Unattended Payment Solution","vendor":"KioSoft","versions":[{"status":"affected","version":"Current firmware/hardware as of Q2/2025"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:78d3f52d370a3ca1db6b254853dca443d9b255d1b650c651df2ce49b9eed4ebd · sha256:08b45ce3065893a3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:78d3f52d370a3ca1db6b254853dca443d9b255d1b650c651df2ce49b9eed4ebd · sha256:08b45ce3065893a3… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-922","description":"CWE-922 Insecure Storage of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:78d3f52d370a3ca1db6b254853dca443d9b255d1b650c651df2ce49b9eed4ebd · sha256:08b45ce3065893a3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://seclists.org/fulldisclosure/2025/Sep/33"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78d3f52d370a3ca1db6b254853dca443d9b255d1b650c651df2ce49b9eed4ebd · sha256:08b45ce3065893a3… · /containers/adp/1/references/0
{"tags":["third-party-advisory"],"url":"https://r.sec-consult.com/kiosoft"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78d3f52d370a3ca1db6b254853dca443d9b255d1b650c651df2ce49b9eed4ebd · sha256:08b45ce3065893a3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.