Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2026-32298 Details
Description
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.
A vulnerability exists in the Angeet ES3 KVM due to inadequate sanitization of user-supplied variables in the 'cfg.lua' script. This flaw allows authenticated attackers to execute operating system-level commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:8.5 HIGHVector:CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
CVSS 3.x Severity and Vector Strings:
CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:9.1 CRITICALVector:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 17, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Total
CISA-ADP
Assessed Mar 11, 2026Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network/ | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Broken Link |
| https://www.cve.org/CVERecord?id=CVE-2026-32291 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| angeet es3 kvm firmware | All versions |
CPE
Remediation
| |
| angeet es3 kvm | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Mar 17, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |