CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-32298
Severity
CRITICAL
CVSS
9.1
EPSS
0.65%
Original NVD Description
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.
Related CVEs
Other vulnerabilities affecting the same vendor(s)