A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects
Kiloview NDI N30
and was fixed in Firmware version later than 2.02.0246
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kiloview
Kiloview ndi N30 |
|
| Vendors & Products |
Kiloview
Kiloview ndi N30 |
Tue, 14 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Oct 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246 | |
| Title | API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products | |
| Weaknesses | CWE-287 CWE-290 CWE-346 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published: 2025-10-13T06:57:45.195Z
Updated: 2025-10-14T13:19:43.818Z
Reserved: 2025-08-20T14:20:57.768Z
Link: CVE-2025-9265
Updated: 2025-10-14T13:19:39.963Z
Status : Awaiting Analysis
Published: 2025-10-13T07:15:56.677
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-9265
No data.