$30 IP-KVM Flaws Could Enable BIOS-Level Enterprise Network Attacks
Recent research has identified significant security vulnerabilities in low-cost IP-KVM devices. Nine vulnerabilities have been discovered across devices from four vendors, which could potentially allow these budget management tools to be exploited as…
Recent research has identified significant security vulnerabilities in low-cost IP-KVM devices. Nine vulnerabilities have been discovered across devices from four vendors, which could potentially allow these budget management tools to be exploited as attack platforms.
The vulnerabilities in question affect devices from GL-iNet, Angeet, Sipeed, and JetKVM. These devices, priced between $30 and $100, have become prevalent in enterprise data centers, healthcare facilities, and industrial environments. Despite their affordability, these devices come with considerable security risks.
Security experts have noted that a compromised KVM device can provide attackers with physical-level control over all connected machines, allowing them to bypass operating systems and endpoint security measures.
GL-iNet Comet RM-1: Issues include weak firmware verification, UART root access, insufficient brute-force protection, and insecure initial cloud provisioning. Angeet ES3 KVM: Critical flaws include an unauthenticated file upload vulnerability and an OS command injection bug. Sipeed NanoKVM: Exposed configuration endpoint vulnerability. JetKVM: Issues with insufficient update verification and rate limiting.
Vendor Product CVE Vulnerability CVSS Status
GL-iNet Comet RM-1 CVE-2026-32290 Insufficient firmware verification 4.2 No fix planned
Recent research has identified significant security vulnerabilities in low-cost IP-KVM devices.
GL-iNet Comet RM-1 CVE-2026-32291 UART root access 7.6 No fix planned
GL-iNet Comet RM-1 CVE-2026-32292 Insufficient brute-force protection 5.3 Fixed in v1.8.1 BETA
GL-iNet Comet RM-1 CVE-2026-32293 Insecure initial cloud provisioning 3.1 Fixed in v1.8.1 BETA
Angeet ES3 KVM CVE-2026-32297 Unauthenticated file upload 9.8 No fix available
Angeet ES3 KVM CVE-2026-32298 OS command injection 8.8 No fix available
Sipeed NanoKVM CVE-2026-32296 Configuration endpoint exposure 5.4 Fixed in v2.3.1
JetKVM JetKVM CVE-2026-32294 Insufficient update verification 6.7 Fixed in v0.5.4
JetKVM JetKVM CVE-2026-32295 Insufficient rate limiting 7.3 Fixed in v0.5.4
Security measures must be taken to isolate KVM devices on dedicated networks and prevent exposure to the public internet. Given their ability to operate below the operating system, traditional antivirus and firewall software cannot detect these compromised devices.
Based on reporting by GBHackers.
