PT-2025-25233 · Bosch · Bosch Telex Rdc Server+1
Published
2025-06-10
·
Updated
2025-06-18
·
CVE-2025-29902
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server (affected versions not specified)
Bosch Telex RDC Server (affected versions not specified)
Bosch RTS VLink (affected versions not specified)
Description
The issue allows unauthorized users to execute arbitrary code on the server machine, enabling remote code execution. This vulnerability affects software used in critical environments such as 911 dispatch, public safety, utilities, and transportation.
Recommendations
For Apache HTTP Server, update to a version that includes the fix for this issue.
For Bosch Telex RDC Server, apply the patch issued by Bosch to resolve the vulnerability.
For Bosch RTS VLink, apply the patch issued by Bosch to resolve the vulnerability.
As a temporary workaround, consider restricting access to the server until a patch is applied.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosch Rts Vlink Virtual Matrix
Bosch Telex Rdc Server