A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
History

Mon, 13 Oct 2025 07:15:00 +0000

Type Values Removed Values Added
Description A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
Title API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
Weaknesses CWE-287
CWE-290
CWE-346
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2025-10-13T06:57:45.195Z

Reserved: 2025-08-20T14:20:57.768Z

Link: CVE-2025-9265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-13T07:15:56.677

Modified: 2025-10-13T07:15:56.677

Link: CVE-2025-9265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.