Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Threema Messaging Service Suffers Massive DDoS Attack
August 17, 2026
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Itself
August 17, 2026
Home/CyberSecurity News/Critical Flaws in $30 IP-KVM Devices Expose Enterprises to BIOS-Level Attacks
CyberSecurity News

Critical Flaws in $30 IP-KVM Devices Expose Enterprises to BIOS-Level Attacks

Key Takeaways Cybersecurity researchers have identified nine critical vulnerabilities across four widely used, low-cost IP-KVM devices. These flaws grant attackers BIOS-level control over connected...

Marcus Rodriguez
Marcus Rodriguez
March 23, 2026 3 Min Read
65 0

Key Takeaways

  • Cybersecurity researchers have identified nine critical vulnerabilities across four widely used, low-cost IP-KVM devices.
  • These flaws grant attackers BIOS-level control over connected systems, effectively bypassing operating system security and EDR solutions.
  • The affected devices include models from GL-iNet, Angeet/Yeeso, Sipeed, and JetKVM, with prices ranging from $30 to $100.
  • One vulnerability in the Angeet ES3 KVM achieved a CVSS score of 9.8, indicating critical severity, and enables unauthenticated remote code execution.
  • While some vendors have been notified, immediate mitigation steps are crucial, including network isolation and strict access controls, as patches may not be universally available.

Widespread Vulnerabilities Discovered in Budget IP-KVMs Pose Significant Enterprise Risk

Recent security assessments have unveiled a series of nine severe vulnerabilities spanning four popular, low-cost IP-KVM (Keyboard, Video, Mouse over IP) devices. These critical flaws could allow malicious actors to achieve complete, BIOS-level control over connected systems, rendering traditional operating system security measures and Endpoint Detection and Response (EDR) agents ineffective.

Table Of Content

  • Key Takeaways
  • Widespread Vulnerabilities Discovered in Budget IP-KVMs Pose Significant Enterprise Risk
  • Threat Actors Actively Exploiting KVM Weaknesses
  • Affected Devices and Underlying Flaws
  • What You Should Do

The implications of compromising an IP-KVM device are profound, as it grants an attacker the functional equivalent of direct physical access to every machine linked to the KVM. This privileged access enables adversaries to inject arbitrary keystrokes, initiate boots from removable media to circumvent disk encryption, and modify BIOS settings to disable security features like Secure Boot. Crucially, because KVMs operate at a layer below the host operating system, attackers can maintain complete stealth from host-based security tools, establishing a highly persistent and difficult-to-detect threat vector.

Threat Actors Actively Exploiting KVM Weaknesses

The danger posed by KVM vulnerabilities is not theoretical; it is actively being exploited in real-world scenarios. The FBI has documented investigations into KVM-related threats, and Microsoft has reported that North Korean state-sponsored threat actors are leveraging IP-KVMs to gain remote physical control over corporate laptops. This highlights the urgent need for organizations to address these vulnerabilities.

Furthermore, recent network scans have identified over 1,600 of these budget-friendly devices directly exposed to the public internet. This widespread exposure creates an alarmingly large attack surface that sophisticated threat actors are likely to target.

Affected Devices and Underlying Flaws

The identified vulnerabilities impact devices from four manufacturers: GL-iNet (Comet RM-1), Angeet/Yeeso (ES3 KVM), Sipeed (NanoKVM), and JetKVM (JetKVM). These devices are commonly found in enterprise environments due to their low price point, typically ranging from $30 to $100.

The root cause of these vulnerabilities lies in fundamental security hygiene failures. These include insufficient firmware signature validation, the exposure of debug interfaces, and broken access control mechanisms. A detailed breakdown of the vulnerabilities is provided below:

Vendor Product CVE Vulnerability CVSS 3.1
GL-iNet Comet RM-1 CVE-2026-32290 Insufficient firmware verification 4.2
GL-iNet Comet RM-1 CVE-2026-32291 UART root access 7.6
GL-iNet Comet RM-1 CVE-2026-32292 Insufficient brute-force protection 5.3
GL-iNet Comet RM-1 CVE-2026-32293 Insecure cloud provisioning 3.1
Angeet/Yeeso ES3 KVM CVE-2026-32297 Unauthenticated file upload 9.8
Angeet/Yeeso ES3 KVM CVE-2026-32298 OS command injection 8.8
Sipeed NanoKVM CVE-2026-32296 Configuration endpoint exposure 5.4
JetKVM JetKVM CVE-2026-32294 Insufficient update verification 6.7
JetKVM JetKVM CVE-2026-32295 Insufficient rate limiting 7.3

Among the most critical findings is a vulnerability affecting the Angeet ES3 KVM, identified as CVE-2026-32297. This flaw permits unauthenticated file uploads, which, when combined with a command injection vulnerability (CVE-2026-32298), facilitates pre-authentication remote code execution with root privileges, earning a CVSS score of 9.8. Equally concerning is the GL-iNet Comet RM-1 (CVE-2026-32291), which provides unauthenticated root-level access through its UART interface and relies on easily spoofed MD5 hashes for firmware verification, making it susceptible to malicious firmware updates.

What You Should Do

To fortify enterprise networks against these severe out-of-band management threats, security teams must elevate the status of IP-KVM devices to critical infrastructure. Based on research from Eclypsium, administrators should undertake the following immediate mitigation steps:

  • Isolate KVM Devices: Immediately segment all IP-KVM devices onto dedicated management VLANs. Under no circumstances should these devices be directly exposed to the internet.
  • Implement Strict Access Controls: Access to KVMs should be rigorously protected, requiring strong multi-factor authentication and accessible only via Virtual Private Networks (VPNs).
  • Inventory and Monitor: Conduct a thorough inventory of your environment to identify all deployed KVMs, including any undocumented devices. Continuously monitor outbound network traffic from these devices for any anomalous behavior.
  • Apply Firmware Updates: Regularly check for and apply the latest firmware patches and security updates released by the respective vendors as soon as they become available.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

CanisterWorm Steals npm Tokens via Compromised Publisher Accounts

Next Post

CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Z.ai Launches GLM-5.3, Boosting Cybersecurity and Coding Capabilities
August 17, 2026
Critical GeoServer SQLi Vulnerability Allows Remote Code Execution
August 17, 2026
MessiahGPT AI Model Automates Ransomware and Phishing Attacks
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us