Researchers disclose vulnerabilities in IP KVMs from 4 manufacturers

Researchers disclose vulnerabilities in IP KVMs from 4 manufacturers

Security researchers are raising alarms about vulnerabilities associated with inexpensive devices known as IP KVMs, which can empower both insiders and cybercriminals to exploit network systems. Priced between $30 and $100, these compact devices, roughly the size of a deck of cards, enable administrators to remotely manage machines at the BIOS/UEFI level, the foundational firmware that operates prior to the operating system's boot-up. While IP KVMs offer significant convenience for system administrators, they also pose considerable risks if misconfigured or accessed by unauthorized individuals. The exposure of these devices to the internet amplifies the threat, particularly when they are deployed with inadequate security measures. Additionally, inherent firmware vulnerabilities can allow remote attackers to seize control of the devices. On Tuesday, experts from the cybersecurity firm Eclypsium revealed nine distinct vulnerabilities affecting IP KVMs from four different manufacturers. The most concerning weaknesses could grant unverified hackers root access or enable them to execute malicious software on the devices. According to Eclypsium researchers Paul Asadoorian and Reynaldo Vasquez Garcia, "These are not obscure zero-day vulnerabilities that require extensive reverse engineering. They represent basic security protocols that any networked device should have in place, such as input validation, authentication, cryptographic verification, and rate limiting. We are witnessing the same type of security oversights that troubled early IoT devices a decade ago, now manifesting in devices that essentially provide physical access to everything they connect with."

Sources : Ars Technica

Published On : Mar 17, 2026, 17:10

Mobile
Google Maps Unveils Innovative ‘Ask Maps’ Feature in India, Enhancing User Experience with AI

Google Maps has recently launched an exciting new chat feature called 'Ask Maps,' powered by its Gemini AI technology. I...

Business Today | Mar 31, 2026, 08:05
Google Maps Unveils Innovative ‘Ask Maps’ Feature in India, Enhancing User Experience with AI
Mobile
Airbnb Expands Offerings with New Private Car Service in 125 Cities

Airbnb has unveiled an exciting new addition to its suite of services, launching a private car pick-up option that will ...

TechCrunch | Mar 31, 2026, 09:15
Airbnb Expands Offerings with New Private Car Service in 125 Cities
Cybersecurity
New IT Regulations Could Transform Social Media News Landscape

On March 30, the Indian Ministry of Information Technology unveiled a proposal aimed at tightening regulations for major...

Business Today | Mar 31, 2026, 05:50
New IT Regulations Could Transform Social Media News Landscape
AI
A Surprising Shift: 15% of Americans Open to AI Bosses, Poll Reveals

In a striking revelation, a recent Quinnipiac University survey has indicated that 15% of Americans are open to the idea...

TechCrunch | Mar 31, 2026, 24:00
A Surprising Shift: 15% of Americans Open to AI Bosses, Poll Reveals
Startups
European Defense Startups Seize Opportunities Amid Rising Middle East Tensions

In the wake of escalating conflicts in the Middle East, particularly following the Iran war, European defense technology...

CNBC | Mar 31, 2026, 09:15
European Defense Startups Seize Opportunities Amid Rising Middle East Tensions
View All News