VYPR

Es3 Kvm Firmware

by Angeet

CVEs (3)

  • CVE-2026-32298CriMar 17, 2026
    risk 0.59cvss 9.1epss 0.01

    The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.

  • CVE-2026-32297HigMar 17, 2026
    risk 0.49cvss 7.5epss 0.01

    The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system binaries could allow an attacker to take complete control of a vulnerable system.

  • CVE-2022-4636Jan 10, 2023
    risk 0.00cvss epss 0.01

    Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.

VYPR — Vulnerability Intelligence