Critical severity9.1NVD Advisory· Published Mar 17, 2026· Updated Apr 27, 2026
CVE-2026-32298
CVE-2026-32298
Description
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.
Affected products
1- cpe:2.3:o:angeet:es3_kvm_firmware:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network/nvdThird Party Advisory
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.jsonnvdBroken Link
- www.cve.org/CVERecordnvdNot Applicable
News mentions
0No linked articles in our index yet.