Vulnerabilities (CVE)

Filtered by vendor Angeet Subscribe
Filtered by product Es3 Kvm
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32298 1 Angeet 2 Es3 Kvm, Es3 Kvm Firmware 2026-04-27 N/A 9.1 CRITICAL
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.
CVE-2026-32297 1 Angeet 2 Es3 Kvm, Es3 Kvm Firmware 2026-04-27 N/A 7.5 HIGH
The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or system binaries. Modified configuration files or system binaries could allow an attacker to take complete control of a vulnerable system.