
Cybersecurity experts are raising concerns about the potential risks associated with inexpensive IP KVM (Keyboard, Video, Mouse over Internet Protocol) devices, as they could give attackers significant control over affected computers.
Eclypsium identified nine security weaknesses in four different products: GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM. The most critical flaws could allow unauthorized individuals to gain root privileges or execute harmful code.
“The consistent problems found are alarming: missing checks for valid firmware signatures, no protection against brute-force attacks, flawed access management, and exposed debugging interfaces,” researchers Paul Asadoorian and Reynaldo Vasquez Garcia stated in their analysis.
Because IP KVM devices allow remote control of a computer’s keyboard, video, and mouse at the BIOS/UEFI level, exploiting vulnerabilities in these devices can put systems at risk of being taken over, bypassing established security measures. The list of deficiencies includes –
“These are not complex zero-day exploits that require extensive reverse engineering,” the researchers pointed out. “These are basic security measures that every networked device should have, such as input validation, authentication, cryptographic verification, and rate limiting. We’re seeing the same types of failures that plagued early IoT devices a decade ago, but now on a device that provides physical-level access to everything it’s connected to.”
Attackers could exploit these vulnerabilities to inject keystrokes, boot from removable media to bypass disk encryption or Secure Boot, bypass lock screens to access systems, and, importantly, remain hidden from security software running at the operating system level.
This is not the first time vulnerabilities in IP KVM devices have been revealed. In July 2025, the Russian cybersecurity firm Positive Technologies reported five vulnerabilities in ATEN International switches (CVE-2025-3710, CVE-2025-3711, CVE-2025-3712, CVE-2025-3713, and CVE-2025-3714) that could lead to denial-of-service attacks or remote code execution.
Furthermore, IP KVM switches like PiKVM or TinyPilot have been used by North Korean IT workers based in countries like China to remotely access company laptops hosted on laptop farms.
Recommended security measures include enabling multi-factor authentication (MFA) where possible, isolating KVM devices on a separate management VLAN, restricting internet access, using tools like Shodan to check for external exposure, monitoring network traffic to and from the devices for unusual activity, and keeping the firmware updated.
“A compromised KVM is different from a compromised IoT device on your network. It provides a direct, silent route to every machine it controls,” Eclypsium stated. “An attacker who gains control of the KVM can hide tools and backdoors on the device itself, allowing them to repeatedly reinfect host systems even after they’ve been cleaned.”
“Because many of these devices lack signature verification for firmware updates, an attacker could tamper with the firmware during distribution and have it persist indefinitely.”
#access #affecting #allow #critical #flaws #four #kvm #login, #news #root #vendors. #without — News
© Bulletproof Servers. All rights reserved.