logo

9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors

ID: a82b3746-b684-5a68-8d4d-c5bac0c9a6c6

STIX ID: report--a82b3746-b684-5a68-8d4d-c5bac0c9a6c6

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers at Eclypsium disclosed nine vulnerabilities across four low-cost IP KVM products that range from insufficient firmware signature verification and missing authentication to UART root access and command injection; several have high CVSS scores (including 9.8 and 8.8) and some remain unpatched. Because IP KVMs provide BIOS/UEFI-level keyboard/video/mouse access, successful exploitation can enable persistent, stealthy full-system takeover (bypassing disk encryption, Secure Boot, and OS-level detection); recommended mitigations include enforcing MFA, isolating KVM devices on management VLANs, restricting Internet exposure, monitoring traffic, and applying available firmware fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.