Vulnerability in KioSoft Unattended Payment Solutions Affecting NFC Card Security
CVE-2025-8699

9.1CRITICAL

Key Information:

Vendor

KiOSoft

Vendor
CVE Published:
12 September 2025

What is CVE-2025-8699?

KioSoft's Stored Value Unattended Payment Solutions leverage insecure MiFare Classic NFC cards, allowing attackers to manipulate card balances. Exploiting this vulnerability, a threat actor can intercept and alter the cash value stored on the card. This is made possible by analyzing card dumps to locate cash value fields, along with a checksum generated using an unknown value. By modifying these fields, unauthorized amounts, potentially up to $655.35, can be loaded onto these cards, enabling fraudulent purchases.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Stored Value Unattended Payment Solution Current firmware/hardware as of Q2/2025

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steffen Robertz, SEC Consult Vulnerability Lab
.