Critical Flaws in KiloView Devices Enable Complete Admin Takeover
The Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability in several versions of KiloView Encoder Series devices. This flaw enables unauthenticated attackers to gain full administrative access.
The Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability in several versions of KiloView Encoder Series devices. This flaw enables unauthenticated attackers to gain full administrative access.
Released under alert code ICSA-26-029-01 on January 29, 2026, the vulnerability has been assigned a CVSS v3 score of 9.8, indicating a high level of risk to affected systems.
The vulnerability, labeled CVE-2026-1453, arises from the absence of authentication for key administrative functions.
Vulnerability CVSS Score Vendor Equipment Type
CVE-2026-1453 9.8 KiloView KiloView Encoder Series Missing Authentication for Critical Function
Exploiting this vulnerability allows attackers to create or delete administrator accounts without authorization, granting them total control over the devices. This represents a significant security issue that remote, unauthenticated actors can exploit.
The Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability in several versions of KiloView Encoder Series devices.
KiloView Encoder devices are extensively used in critical infrastructure sectors, including communications and information technology. The manufacturer, based in China, provides encoding equipment globally, making this vulnerability a significant concern for organizations worldwide.
The issue affects multiple hardware versions and firmware builds across eight encoder series variants, such as the E1, E2, G1, P1, P2, and RE1 lines.
Researcher Muhammad Ammar (0xam225) discovered and reported the vulnerability to CISA, adhering to responsible disclosure practices. No active exploitation has been observed thus far, but the critical nature of the flaw necessitates prompt remediation.
CISA advises immediate defensive actions, including network isolation of affected devices and limiting their Internet accessibility. Organizations should position control system networks behind firewalls and separate them from business networks.
If remote access is unavoidable, it is recommended to employ Virtual Private Networks (VPNs) with up-to-date security patches, while acknowledging that VPNs have their own vulnerabilities.
Organizations should minimize network exposure for all control system devices and assess risk before applying defensive measures. CISA encourages a defense-in-depth strategy and comprehensive cybersecurity planning for industrial control systems.
Currently, there are no reports of public exploitation of this vulnerability, providing a critical period for organizations to implement patches before potential exploitation by attackers.
Based on reporting by GBHackers.
