CVE-2026-32298

CRITICAL

Angeet ES3 KVM OS command injection

Title source: cna
STIX 2.1

Description

The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.

Scores

CVSS v3 9.1
EPSS 0.0065
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
ANGEET/ES3 KVM
angeet/es3_kvm_firmware
Published Mar 17, 2026
Tracked Since Mar 17, 2026