$30 IP-KVM Flaws Could Give Attackers BIOS-Level Control Across Enterprise Networks
Recent research has identified nine critical vulnerabilities in four widely used low-cost IP-KVM devices. These security flaws allow attackers to obtain complete, BIOS-level control over connected systems, effectively bypassing operating system security…
Recent research has identified nine critical vulnerabilities in four widely used low-cost IP-KVM devices. These security flaws allow attackers to obtain complete, BIOS-level control over connected systems, effectively bypassing operating system security controls and Endpoint Detection and Response (EDR) agents .
Compromised Keyboard, Video, and Mouse (KVM) devices grant attackers the equivalent of physical access to every connected machine. This allows them to inject keystrokes, boot from removable media to bypass encryption, and modify BIOS setups to disable Secure Boot. Operating below the host operating system, KVM devices make attackers invisible to host-based security tools, creating a persistent threat vector.
The vulnerabilities, actively exploited in the wild, have been under investigation by the FBI. Microsoft has documented threats from North Korean state-sponsored actors using IP-KVMs to gain remote control over corporate laptops.
Over 1,600 of these low-cost devices have been identified as directly exposed to the internet, significantly expanding the attack surface for malicious actors. The affected devices, ranging from $30 to $100, are from vendors including GL-iNet, Angeet/Yeeso, Sipeed, and JetKVM. The vulnerabilities are due to basic security hygiene failures such as missing firmware signature validation, exposed debug interfaces, and inadequate access controls.
Vendor Product CVE Vulnerability CVSS 3.1
GL-iNet Comet RM-1 CVE-2026-32290 Insufficient firmware verification 4.2
GL-iNet Comet RM-1 CVE-2026-32291 UART root access 7.6
Recent research has identified nine critical vulnerabilities in four widely used low-cost IP-KVM devices.
GL-iNet Comet RM-1 CVE-2026-32292 Insufficient brute-force protection 5.3
GL-iNet Comet RM-1 CVE-2026-32293 Insecure cloud provisioning 3.1
Angeet/Yeeso ES3 KVM CVE-2026-32297 Unauthenticated file upload 9.8
Angeet/Yeeso ES3 KVM CVE-2026-32298 OS command injection 8.8
Sipeed NanoKVM CVE-2026-32296 Configuration endpoint exposure 5.4
JetKVM JetKVM CVE-2026-32294 Insufficient update verification 6.7
JetKVM JetKVM CVE-2026-32295 Insufficient rate limiting 7.3
The most critical issue is with the Angeet ES3 KVM, containing an unauthenticated file upload vulnerability leading to remote code execution with root privileges when paired with a command injection flaw. The GL-iNet Comet RM-1 is similarly vulnerable, providing root-level access via its UART interface and using weak MD5 hash verification for firmware updates.
To safeguard against these out-of-band management threats, it is critical to treat IP-KVM devices as essential infrastructure. According to Eclypsium research , administrators should isolate KVM devices on dedicated management VLANs and prevent direct internet exposure. Access should be controlled using strong authentication and Virtual Private Networks (VPNs) .
Organizations should inventory and document all KVM devices, monitor network traffic for irregularities, and apply the latest firmware patches provided by vendors.
Based on reporting by Cyber Security News.
