VYPR

ES3 KVM

by Angeet

CVEs (2)

  • CVE-2026-32298CriMar 17, 2026
    risk 0.59cvss 9.1epss 0.00

    The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.

  • CVE-2026-32297HigMar 17, 2026
    risk 0.49cvss 7.5epss 0.00

    The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system binaries could allow an attacker to take complete control of a vulnerable system.