Cheap IP KVMs: Security Flaws Offer Deep Access to Systems

by Anika Shah - Technology
0 comments

Cheap KVMs: A Hidden Gateway for Cyberattacks

A surge in low-cost keyboard, video, and mouse (KVM) devices is raising significant security concerns. These internet-connected tools, designed for remote server and human-machine interface (HMI) control, operate at the Unified Extensible Firmware Interface (UEFI) level, making them a potentially dangerous entry point for attackers.

The Rise of Low-Cost KVMs and the Security Risks

Traditionally, KVMs were expensive, rack-mounted devices. Now, they are readily available for under $100, increasing their adoption but likewise expanding the attack surface. Unlike remote management tools that require a loaded operating system, KVMs operate at the UEFI level, granting attackers access below the operating system and bypassing traditional security measures like endpoint detection and response (EDR) and antivirus software.

According to firmware security firm Eclypsium, compromising a KVM device provides an attacker with the equivalent of physical access to every connected machine. This includes complete keyboard, video, and mouse control at the BIOS level.1 Once in control, attackers can inject keystrokes, boot into BIOS or safe mode, and persistently reinfect systems.

Vulnerabilities Discovered in KVM Devices

Eclypsium’s recent probe of devices from four KVM vendors revealed nine vulnerabilities. Common issues include missing firmware signature validation, lack of brute-force protection, broken access controls, and exposed debug interfaces – fundamental security hygiene failures.1

The most critical vulnerability, CVE-2026-32297, affects the Angeet ES3 KVM model (also sold under the Yesso brand). This flaw exposes an endpoint allowing unauthenticated attackers with network access to upload arbitrary files to the device. Another vulnerability, CVE-2026-32298, enables attackers to inject root commands through the conf.lua configuration script due to a lack of input sanitization.1 While Angeet has committed to addressing these flaws, a timeline for patching remains unclear.

Previous Warnings and Emerging Threats

Eclypsium isn’t the first to raise concerns about KVM security. RunZero previously identified flaws in newer KVM models, including charging for authentication features, unresolved software vulnerabilities, and overly detailed configuration disclosures.1

KVMs have also been linked to activity by North Korean IT workers, who apply them to mask their location while accessing company laptops.1

The Growing Threat Landscape

While widespread exploitation of these vulnerabilities hasn’t been observed yet, security researchers anticipate attacks will increase as KVMs become more prevalent and attract attacker attention. Paul Asadoorian, principal security researcher at Eclypsium, notes that KVMs provide a “great place to hide” for attackers.1

The recent discovery of the “Cyber Android RAT” marketed for global buyers, capable of capturing WhatsApp history and crypto seed phrases, highlights the broader trend of sophisticated surveillance tools becoming readily available to cybercriminals.4 This underscores the importance of securing all remote access points, including KVM devices.

Simultaneously, a three-year-aged zero-day flaw in Cisco SD-WAN software is under mass attack, demonstrating the ongoing exploitation of known vulnerabilities.2 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive for federal agencies to patch the Cisco flaw within two days.2

Related Posts

Leave a Comment