Vulnerabilities · 180 days ago
Eclypsium disclosed nine vulnerabilities in low-cost IP KVMs from four manufacturers. The most severe allow unauthenticated root access or remote code execution and expose BIOS/UEFI-level control, increasing host takeover risk.
CVEs in this update
10 CVEs
2 critical · 4 high · 3 medium · 1 low
0 in CISA KEV · 1 with EPSS above 1%
Highest severity: CVE-2025-3710 · 9.8 CRITICAL
Highest EPSS: CVE-2025-3710 · 1.5%
3 sources covering this story
That cheap KVM device could expose your network to remote compromise
Vulnerabilities found in low-cost KVM devices can give attackers the equivalent of physical access to everything they connect to.
9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors
Researchers uncovered 9 vulnerabilities across 4 IP KVM devices enabling unauthenticated root access and code execution.
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
Internet-exposed devices that give BIOS-level access?
Part of the PlainSec briefing for 2026-03-19