← voltar
CVE-2025-9265criticalCWE-287CWE-290CWE-346

API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products

28Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 10epss 0.2%
probabilidade de exploração
0.2%top 84% das CVEs
exploração observada
nãonenhuma fonte reporta
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Produtos afetados
Kiloview · NDI