PT-2025-25233 · Bosch · Bosch Telex Rdc Server+1

Published

2025-06-10

·

Updated

2025-06-18

·

CVE-2025-29902

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server (affected versions not specified) Bosch Telex RDC Server (affected versions not specified) Bosch RTS VLink (affected versions not specified)
Description The issue allows unauthorized users to execute arbitrary code on the server machine, enabling remote code execution. This vulnerability affects software used in critical environments such as 911 dispatch, public safety, utilities, and transportation.
Recommendations For Apache HTTP Server, update to a version that includes the fix for this issue. For Bosch Telex RDC Server, apply the patch issued by Bosch to resolve the vulnerability. For Bosch RTS VLink, apply the patch issued by Bosch to resolve the vulnerability. As a temporary workaround, consider restricting access to the server until a patch is applied.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08212
CVE-2025-29902

Affected Products

Bosch Rts Vlink Virtual Matrix
Bosch Telex Rdc Server