Critical Flaws in $30 IP-KVM Devices Expose Enterprises to BIOS-Level Attacks
Key Takeaways Cybersecurity researchers have identified nine critical vulnerabilities across four widely used, low-cost IP-KVM devices. These flaws grant attackers BIOS-level control over connected...
Key Takeaways
- Cybersecurity researchers have identified nine critical vulnerabilities across four widely used, low-cost IP-KVM devices.
- These flaws grant attackers BIOS-level control over connected systems, effectively bypassing operating system security and EDR solutions.
- The affected devices include models from GL-iNet, Angeet/Yeeso, Sipeed, and JetKVM, with prices ranging from $30 to $100.
- One vulnerability in the Angeet ES3 KVM achieved a CVSS score of 9.8, indicating critical severity, and enables unauthenticated remote code execution.
- While some vendors have been notified, immediate mitigation steps are crucial, including network isolation and strict access controls, as patches may not be universally available.
Widespread Vulnerabilities Discovered in Budget IP-KVMs Pose Significant Enterprise Risk
Recent security assessments have unveiled a series of nine severe vulnerabilities spanning four popular, low-cost IP-KVM (Keyboard, Video, Mouse over IP) devices. These critical flaws could allow malicious actors to achieve complete, BIOS-level control over connected systems, rendering traditional operating system security measures and Endpoint Detection and Response (EDR) agents ineffective.
Table Of Content
The implications of compromising an IP-KVM device are profound, as it grants an attacker the functional equivalent of direct physical access to every machine linked to the KVM. This privileged access enables adversaries to inject arbitrary keystrokes, initiate boots from removable media to circumvent disk encryption, and modify BIOS settings to disable security features like Secure Boot. Crucially, because KVMs operate at a layer below the host operating system, attackers can maintain complete stealth from host-based security tools, establishing a highly persistent and difficult-to-detect threat vector.
Threat Actors Actively Exploiting KVM Weaknesses
The danger posed by KVM vulnerabilities is not theoretical; it is actively being exploited in real-world scenarios. The FBI has documented investigations into KVM-related threats, and Microsoft has reported that North Korean state-sponsored threat actors are leveraging IP-KVMs to gain remote physical control over corporate laptops. This highlights the urgent need for organizations to address these vulnerabilities.
Furthermore, recent network scans have identified over 1,600 of these budget-friendly devices directly exposed to the public internet. This widespread exposure creates an alarmingly large attack surface that sophisticated threat actors are likely to target.
Affected Devices and Underlying Flaws
The identified vulnerabilities impact devices from four manufacturers: GL-iNet (Comet RM-1), Angeet/Yeeso (ES3 KVM), Sipeed (NanoKVM), and JetKVM (JetKVM). These devices are commonly found in enterprise environments due to their low price point, typically ranging from $30 to $100.
The root cause of these vulnerabilities lies in fundamental security hygiene failures. These include insufficient firmware signature validation, the exposure of debug interfaces, and broken access control mechanisms. A detailed breakdown of the vulnerabilities is provided below:
| Vendor | Product | CVE | Vulnerability | CVSS 3.1 |
|---|---|---|---|---|
| GL-iNet | Comet RM-1 | CVE-2026-32290 | Insufficient firmware verification | 4.2 |
| GL-iNet | Comet RM-1 | CVE-2026-32291 | UART root access | 7.6 |
| GL-iNet | Comet RM-1 | CVE-2026-32292 | Insufficient brute-force protection | 5.3 |
| GL-iNet | Comet RM-1 | CVE-2026-32293 | Insecure cloud provisioning | 3.1 |
| Angeet/Yeeso | ES3 KVM | CVE-2026-32297 | Unauthenticated file upload | 9.8 |
| Angeet/Yeeso | ES3 KVM | CVE-2026-32298 | OS command injection | 8.8 |
| Sipeed | NanoKVM | CVE-2026-32296 | Configuration endpoint exposure | 5.4 |
| JetKVM | JetKVM | CVE-2026-32294 | Insufficient update verification | 6.7 |
| JetKVM | JetKVM | CVE-2026-32295 | Insufficient rate limiting | 7.3 |
Among the most critical findings is a vulnerability affecting the Angeet ES3 KVM, identified as CVE-2026-32297. This flaw permits unauthenticated file uploads, which, when combined with a command injection vulnerability (CVE-2026-32298), facilitates pre-authentication remote code execution with root privileges, earning a CVSS score of 9.8. Equally concerning is the GL-iNet Comet RM-1 (CVE-2026-32291), which provides unauthenticated root-level access through its UART interface and relies on easily spoofed MD5 hashes for firmware verification, making it susceptible to malicious firmware updates.
What You Should Do
To fortify enterprise networks against these severe out-of-band management threats, security teams must elevate the status of IP-KVM devices to critical infrastructure. Based on research from Eclypsium, administrators should undertake the following immediate mitigation steps:
- Isolate KVM Devices: Immediately segment all IP-KVM devices onto dedicated management VLANs. Under no circumstances should these devices be directly exposed to the internet.
- Implement Strict Access Controls: Access to KVMs should be rigorously protected, requiring strong multi-factor authentication and accessible only via Virtual Private Networks (VPNs).
- Inventory and Monitor: Conduct a thorough inventory of your environment to identify all deployed KVMs, including any undocumented devices. Continuously monitor outbound network traffic from these devices for any anomalous behavior.
- Apply Firmware Updates: Regularly check for and apply the latest firmware patches and security updates released by the respective vendors as soon as they become available.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.