CVE-2025-9265 Details
Description
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects Kiloview NDI N30 and was fixed in Firmware version later than 2.02.0246
A broken authorization vulnerability exists in Kiloview NDI N30, allowing remote unauthenticated attackers to disable user verification. This exploitation grants access to state-changing actions that are intended for administrators only. The vulnerability has been addressed in firmware versions later than 2.02.0246.
Users can upgrade to Kiloview NDI N30 firmware version 3.01, released on October 11, 2025. This version includes security enhancements that address this vulnerability. However, upgrading from version 2.x to 3.01 requires first installing an intermediate upgrade package, N30-9999-upgrade-firmware, followed by the upgrade to version 3.01.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 13, 2025CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kiloview.com/en/support/download/n30-firmware-downloadlatest/ | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Kiloview NDI N30 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 13, 2025 | New CVE Received | [email protected] |
Volerion