CVE-2025-63560 Product: KiloView Dual-Channel 4K HDMI & 3G-SDI HEVC Video Encoder - Firmware Version 1.20.0006 Summary: An unauthenticated API endpoint on KiloView E3 video encoders allowed remote attackers to trigger a factory reset without any credentials or prior authentication. If the device remained reachable after the reset, it was accessible via default credentials, allowing full dashboard and video feed access. Poc: - Warning: The vulnerable endpoint triggers a factory reset. Do not run against devices you do not own or control. The placeholder should be replaced with the IP address used to reach the device's web interface. - Full Write-Up: Link