Researchers disclosed multiple vulnerabilities affecting internet-connected IP KVM devices from GL-iNet, JetKVM, Sipeed, and Angeet/Yeeso, warning that compromise of these products can give attackers effective BIOS- and UEFI-level keyboard, video, and mouse access to connected systems. Reported flaws include OS command injection, unauthenticated file access, weak firmware authenticity verification, exposed configuration endpoints, insecure provisioning, and insufficient brute-force or rate-limiting protections. The most severe issues were reported in Angeet/Yeeso ES3 KVM devices, including CVE-2026-32297 and CVE-2026-32298, with no fixes available at publication, while other vendors had released patches or beta updates for some affected products.
The disclosures highlight a broader risk from the rapid spread of inexpensive remote-management hardware that operates below the operating system and outside the visibility of many endpoint defenses. Security researchers and industry experts warned that a compromised IP KVM can provide attackers with the equivalent of physical access to attached machines, enabling keystroke injection, BIOS manipulation, safe-mode booting, and persistent reinfection. Internet scanning cited in coverage found more than 1,300 exposed devices, underscoring that the issue is not limited to product flaws alone but also to unsafe deployment of these management interfaces on reachable networks.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
A March 23, 2026 reference said more than 1,600 IP KVM devices were directly exposed to the internet, indicating continued growth from the more than 1,300 systems previously reported. The higher count reinforced concerns that vulnerable low-cost KVMs remained broadly reachable online.
Following disclosure, Eclypsium and runZero recommended that administrators scan for overlooked IP KVMs, restrict internet exposure, isolate them on separate networks where possible, use strong passwords, and access them through reputable VPNs such as WireGuard or Tailscale.
By March 2026, runZero founder HD Moore reported finding more than 1,300 internet-exposed IP KVM devices, up from about 1,000 the previous June. The increase reinforced concerns that vulnerable KVMs were both discoverable and growing in number online.
At the time of disclosure, Angeet/Yeeso had not committed fixes for its two most severe vulnerabilities, while Sipeed and JetKVM had released fixes or beta fixes for some issues and GL-iNet had planned or beta remediations for others. This established that patch availability varied significantly across affected vendors.
On publication of its March 2026 report, Eclypsium warned that low-cost internet-connected IP KVMs can provide attackers BIOS/UEFI-level control over attached systems. The disclosure highlighted severe Angeet/Yeeso ES3 flaws, including unauthenticated file upload and root command injection vulnerabilities.
Eclypsium researchers Reynaldo Vasquez Garcia and Paul Asadoorian analyzed IP KVM products from GL-iNet, Angeet/Yeeso, Sipeed, and JetKVM and found nine vulnerabilities. The issues included missing firmware signature validation, weak access controls, exposed debug interfaces, and lack of brute-force protection.
runZero had identified roughly 1,000 IP KVM devices exposed to the internet by June 2025, establishing an early warning sign that these systems were broadly reachable online.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
eclypsium.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcecsoonline.com
Open sourceeclypsium.com
Open sourceeclypsium.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.