Vulnerabilities · 180 days ago

IP KVM Flaws Allow Unauthenticated Root Access and Takeover

Eclypsium disclosed nine vulnerabilities in low-cost IP KVMs from four manufacturers. The most severe allow unauthenticated root access or remote code execution and expose BIOS/UEFI-level control, increasing host takeover risk.

CVEs in this update

10 CVEs

2 critical · 4 high · 3 medium · 1 low

0 in CISA KEV · 1 with EPSS above 1%

Highest severity: CVE-2025-3710 · 9.8 CRITICAL

Highest EPSS: CVE-2025-3710 · 1.5%

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-19

Editions

Related stories