Vulnerabilities & Exploits · IoT / OT Attack

IP KVM Flaws Allow Unauthenticated Root Access and Takeover

Eclypsium disclosed nine vulnerabilities in low-cost IP KVMs from four manufacturers. The most severe allow unauthenticated root access or remote code execution and expose BIOS/UEFI-level control, increasing host takeover risk.

3 sources · Mar 20

CVEs in this update

10 CVEs

2 critical · 4 high · 3 medium · 1 low

0 in CISA KEV · 1 with EPSS above 1%

Highest severity: CVE-2025-3710 · 9.8 CRITICAL

Highest EPSS: CVE-2025-3710 · 1.5%

Timeline

Sources

Part of the PlainSec briefing for 2026-03-18

Every edition of this story: IP KVM Flaws Allow Unauthenticated Root Access and Takeover

More from today