CVE-2026-32294

MEDIUM

JetKVM insufficient firmware verification

Title source: cna
STIX 2.1

Description

JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.

Scores

CVSS v3 4.7
EPSS 0.0000
EPSS Percentile 0.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-345 CWE-347
Status published
Products (3)
JetKVM/JetKVM < 0.5.4
JetKVM/JetKVM 0.5.4
jetkvm/kvm < 0.5.3
Published Mar 17, 2026
Tracked Since Mar 17, 2026