← back
CVE-2023-41917criticalCWE-20

Improper input validation in Kiloview P1/P2 devices allows for remote code execution

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 0.7%
exploitation probability
0.7%top 48% of all CVEs
observed exploitation
nono source reports it
Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement feature, enabling unauthorized code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Kiloview · P1/P2