Vulnerability in KioSoft Unattended Payment Solutions Affecting NFC Card Security
CVE-2025-8699

Currently unrated

Key Information:

Vendor

KiOSoft

Vendor
CVE Published:
12 September 2025

What is CVE-2025-8699?

KioSoft's Stored Value Unattended Payment Solutions leverage insecure MiFare Classic NFC cards, allowing attackers to manipulate card balances. Exploiting this vulnerability, a threat actor can intercept and alter the cash value stored on the card. This is made possible by analyzing card dumps to locate cash value fields, along with a checksum generated using an unknown value. By modifying these fields, unauthorized amounts, potentially up to $655.35, can be loaded onto these cards, enabling fraudulent purchases.

Affected Version(s)

Stored Value Unattended Payment Solution Current firmware/hardware as of Q2/2025

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steffen Robertz, SEC Consult Vulnerability Lab
.
CVE-2025-8699 : Vulnerability in KioSoft Unattended Payment Solutions Affecting NFC Card Security