IP KVM Flaws Allow Unauthenticated Root Access and Takeover

Eclypsium disclosed nine vulnerabilities in low-cost IP KVMs from four manufacturers. The most severe allow unauthenticated root access or remote code execution and expose BIOS/UEFI-level control, increasing host takeover risk.

Part of the PlainSec briefing for 2026-03-19

Sources