Junglewise Threat Intelligence

CVE-2025-63560: Kiloview E3 Video Encoder unauthenticated factory reset in systemctrl API

CVE-2025-63560 · Severity: high · CVSS 7.5 · Published 2025-11-06

Executive brief

A vulnerability in Kiloview E3 video encoders allows unauthorized individuals to remotely trigger a factory reset of the device. This hardware is typically used for professional video broadcasting and streaming; an exploit would cause an immediate service outage. In some cases, the reset may also restore default login credentials, potentially allowing an attacker to take full control of the video feed and device settings.

Technical details

An unauthenticated API endpoint exists in the Kiloview E3 Dual Channel 4K HDMI & 3G-SDI HEVC Video Encoder firmware version 1.20.0006. The 'systemctrl/system/reFactory' component of the systemctrl API does not enforce authorization for functions without parameters. A remote, unauthenticated attacker can send a direct HTTP request to this endpoint to trigger a factory reset. This results in a Denial of Service (DoS) as the device wipes its configuration. If the device remains network-accessible after the reset, it reverts to default credentials, which may allow an attacker to gain administrative access. The vendor reportedly patched this vulnerability in July 2025.

Affected products

  • Kiloview E3 Video Encoder Firmware 1.20.0006

Timeline

  • 2025-04-06: other: Vulnerability discovered
  • 2025-04-07: disclosed: Disclosed to vendor
  • 2025-07-21: patched: Vendor released patch
  • 2025-07-25: disclosed: Public disclosure of exploit details
  • 2025-11-06: advisory: CVE assigned and published

References