Vulnerabilities (CVE)

Filtered by vendor Jetkvm Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32294 1 Jetkvm 1 Kvm 2026-04-10 N/A 4.7 MEDIUM
JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.
CVE-2026-32295 1 Jetkvm 1 Kvm 2026-04-10 N/A 7.5 HIGH
JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.