CVE-2023-41920: Kiloview p1/p2

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.

Affected products

  • Kiloview p1/p2: up to and including 4.8.2605
  • Kiloview p1 4g Video Encoder Firmware: any version
  • Kiloview p2 4g Video Encoder Firmware: any version

Published 2024-07-02. Last modified 2026-06-17.