CVE-2025-8699 describes a critical vulnerability in KioSoft's "Stored Value" Unattended Payment Solutions, where insecure MiFare Classic NFC cards are used. Attackers can manipulate the card's balance by identifying and altering the cash value and checksum fields, allowing them to load arbitrary amounts of money (up to $65,535) onto the card. This vulnerability carries a CVSS score of 9.1 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality and integrity, enabling unauthorized financial gain. While not currently listed in CISA's KEV catalog or having public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| KioSoft | Stored Value Unattended Payment Solution | Current firmware/hardware as of Q2/2025CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.