CVE-2026-32296 Details
Description
Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthenticated attacker with network access to change the saved configured Wi-Fi network to one of the attacker's choosing, or craft a request to exhaust the system memory and terminate the KVM process.
A vulnerability in Sipeed NanoKVM versions prior to 2.3.1 allows an unauthenticated attacker with network access to exploit a Wi-Fi configuration endpoint that lacks proper security checks. This exploitation could lead to unauthorized changes in the saved Wi-Fi network settings or be used to craft requests that exhaust system memory, causing the KVM process to terminate.
Users can update to Sipeed NanoKVM version 2.3.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 17, 2026CISA-ADP
Assessed Mar 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network/ | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://github.com/sipeed/NanoKVM/blob/main/CHANGELOG.md#231-2025-12-26 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://www.cve.org/CVERecord?id=CVE-2026-32296 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |