CVE-2025-8915 Details
Description
Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-in-the-middle attack via the network
A vulnerability in Kiloview N30 firmware version 2.02.246 has been identified, involving a hardcoded TLS private key and certificate. This flaw allows a malicious adversary to perform a man-in-the-middle attack over the network.
Users can upgrade to Kiloview N30 firmware version 3.01, which addresses this vulnerability. However, upgrading from version 2.x to 3.01 requires first installing an intermediate upgrade package, N30-9999-upgrade-firmware.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 13, 2025CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kiloview.com/en/support/download/n30-firmware-downloadlatest/ | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kiloview N30 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 13, 2025 | New CVE Received | [email protected] |
Volerion