# CVE-2025-9265

## Summary

- **CVE ID:** CVE-2025-9265
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-346, CWE-290, CWE-287
- **Published:** Oct 13, 2025
- **Last Modified:** Mar 12, 2026

## Description

A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affects 

 Kiloview NDI N30

and was fixed in Firmware version later than  2.02.0246

## Affected Products

- Kiloview — NDI (2.02.246)

## References

- [CNA](https://www.kiloview.com/en/support/download/n30-firmware-downloadlatest/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 13.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._