CVE-2026-32294
JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-03-17 18:16:16
Güncelleme
2026-03-18 14:52:44
Source Identifier
9119a7d8-5eab-497f-8521-727c672e3725
KEV Date Added
-