Researchers have identified nine vulnerabilities in four popular low-cost KVM-over-IP, ranging from unauthenticated command injection to weak authentication defenses and insecure firmware updates. The vulnerabilities are particularly concerning given the growing presence of such devices in enterprise environments, whether intentionally deployed by IT administrators and managed service providers or introduced as shadow IT.
See also: Ukrainian Vishing ring stole 2 million euros from EU citizens

KVM-over-IP devices allow users to control computers remotely as if they were physically present, with full access to keyboard, video and mouse, including BIOS level when the operating system is not running. Businesses have long relied on multi-port KVM switches that include security features such as multi-factor authentication, encryption and logging, but cost hundreds or thousands of dollars.
Lately, smaller businesses and IT teams operating on limited budgets have turned to a new category of compact, Linux KVM-based devices that offer the same access at a fraction of the cost. However, the quality of their firmware and the access controls are not equally strong.
Researchers from security firm Eclypsium have analyzed several of these inexpensive models in recent months and found a lack of brute-force protection for authentication, insecure firmware update mechanisms, exposed diagnostic environments, and unauthenticated vulnerabilities that can lead to complete device takeover.
See also: Phishing: Man targeted NBA, NFL athletes while in federal prison

The number of such devices exposed directly to the internet has increased from a few hundred less than a year ago to over 1,600, according to Eclypsium. This may not sound like a large number, but the users of these devices range from small IT shops and MSPs to enterprises spanning many industry sectors.
The most severe vulnerability, with a CVSS of 9.8, was found in the Angeet/Yeeso ES3 KVM and allows any attacker with network access to write arbitrary files to the device via an unprotected mount point. Combined with a separate command injection vulnerability, it creates the issue for remote code execution with root privileges before authentication. Angeet has committed to fixing the vulnerabilities but has not given Eclypsium a timeline.
A compromised KVM device can become a powerful backdoor in any environment. An attacker can inject keystrokes to execute commands or gain access to UEFI settings to disable security features such as disk encryption and Secure Boot.
Spies from North Korea who pretended to be remote workers have used PiKVM devices connected to laptops and workstations provided by their employers to fake their physical presence in different countries and gain access to corporate networks.
See also: Stryker: Cyberattack deleted data from thousands of devices (no malware)

Eclypsium advises organizations to isolate KVM devices in dedicated management VLANs, not expose them directly to the internet, implement two-factor authentication when available, and use VPN solutions for access. Companies should also monitor their networks for unknown KVM devices and deploy firmware updates when available.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
