Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angeet es3 Kvm Firmware
|
|
| CPEs | cpe:2.3:h:angeet:es3_kvm:*:*:*:*:*:*:*:* cpe:2.3:o:angeet:es3_kvm_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Angeet es3 Kvm Firmware
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angeet
Angeet es3 Kvm |
|
| Vendors & Products |
Angeet
Angeet es3 Kvm |
Tue, 17 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands. | |
| Title | Angeet ES3 KVM OS command injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-03-17T18:09:21.367Z
Reserved: 2026-03-11T18:27:11.768Z
Link: CVE-2026-32298
Updated: 2026-03-17T18:09:18.683Z
Status : Analyzed
Published: 2026-03-17T18:16:17.313
Modified: 2026-04-27T16:58:08.173
Link: CVE-2026-32298
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:49:00Z