CVE-2023-41926: Kiloview p1/p2
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.
Affected products
- Kiloview p1/p2: up to and including 4.8.2605
- Kiloview p1 4g Video Encoder Firmware: any version
- Kiloview p2 4g Video Encoder Firmware: any version
Published 2024-07-02. Last modified 2026-06-17.