Vulnerabilities & Exploits · IoT / OT Attack
IP KVM Flaws Allow Unauthenticated Root Access and Takeover Eclypsium disclosed nine vulnerabilities in low-cost IP KVMs from four manufacturers. The most severe allow unauthenticated root access or remote code execution and expose BIOS/UEFI-level control, increasing host takeover risk.
3 sources · Mar 19
CVEs in this update
10 CVEs
2 critical · 4 high · 3 medium · 1 low
0 in CISA KEV · 1 with EPSS above 1%
Highest severity: CVE-2025-3710 · 9.8 CRITICAL
Highest EPSS: CVE-2025-3710 · 1.5%
Timeline Sources Mar 19 CSO Online
That cheap KVM device could expose your network to remote compromise
Vulnerabilities found in low-cost KVM devices can give attackers the equivalent of physical access to everything they connect to.
original Mar 18 The Hacker News
9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors
Researchers uncovered 9 vulnerabilities across 4 IP KVM devices enabling unauthenticated root access and code execution.
original Mar 17 Ars Technica Security
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
Internet-exposed devices that give BIOS-level access?
original Part of the PlainSec briefing for 2026-03-19
Every edition of this story: IP KVM Flaws Allow Unauthenticated Root Access and Takeover
More from today
Vulnerabilities & Exploits · IoT / OT Attack
IP KVM Flaws Allow Unauthenticated Root Access and Takeover Eclypsium disclosed nine vulnerabilities in low-cost IP KVMs from four manufacturers. The most severe allow unauthenticated root access or remote code execution and expose BIOS/UEFI-level control, increasing host takeover risk.
3 sources · Mar 19
CVEs in this update
10 CVEs
2 critical · 4 high · 3 medium · 1 low
0 in CISA KEV · 1 with EPSS above 1%
Highest severity: CVE-2025-3710 · 9.8 CRITICAL
Highest EPSS: CVE-2025-3710 · 1.5%
Timeline Sources Mar 19 CSO Online
That cheap KVM device could expose your network to remote compromise
Vulnerabilities found in low-cost KVM devices can give attackers the equivalent of physical access to everything they connect to.
original Mar 18 The Hacker News
9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors
Researchers uncovered 9 vulnerabilities across 4 IP KVM devices enabling unauthenticated root access and code execution.
original Mar 17 Ars Technica Security
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
Internet-exposed devices that give BIOS-level access?
original Part of the PlainSec briefing for 2026-03-19
Every edition of this story: IP KVM Flaws Allow Unauthenticated Root Access and Takeover
More from today