CVE-2025-8915
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-13

Last updated on: 2025-10-14

Assigner: Switzerland Government Common Vulnerability Program

Description
Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246Β allows malicious adversary to do a Mann-in-the-middle attack via the network
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-13
Last Modified
2025-10-14
Generated
2026-06-16
AI Q&A
2025-10-13
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
kiloview n30 2.02.246
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves a hardcoded TLS private key and certificate embedded in the firmware of the Kiloview N30 device version 2.02.246. Because these cryptographic credentials are fixed and not unique per device, a malicious attacker can exploit this to perform a man-in-the-middle (MitM) attack over the network, intercepting or altering communications that are supposed to be secure.

Impact Analysis

The vulnerability can allow attackers to intercept, read, or modify sensitive data transmitted over the network by performing a man-in-the-middle attack. This compromises the confidentiality and integrity of communications, potentially leading to data breaches, unauthorized access, and other security incidents.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-8915. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart