Kiloview NDI N30 Broken Authorization Vulnerability Allowing Unauthorized Access to State-Changing Actions
Vulnerability
A broken authorization vulnerability exists in Kiloview NDI N30, allowing remote unauthenticated attackers to disable user verification. This exploitation grants access to state-changing actions that are intended for administrators only. The vulnerability has been addressed in firmware versions later than 2.02.0246.
Impact
Exploitation of this vulnerability could lead to unauthorized access to administrative functions, allowing attackers to perform state-changing actions without proper authorization.
Remediation
Users can upgrade to Kiloview NDI N30 firmware version 3.01, released on October 11, 2025. This version includes security enhancements that address this vulnerability. However, upgrading from version 2.x to 3.01 requires first installing an intermediate upgrade package, N30-9999-upgrade-firmware, followed by the upgrade to version 3.01.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
