HomeTechnologyResearchers disclose vulnerabilities in IP KVMs from four manufacturers

Researchers disclose vulnerabilities in IP KVMs from four manufacturers

TechnologyMarch 17, 2026
1 min read
Researchers disclose vulnerabilities in IP KVMs from four manufacturers
Internet-exposed devices that give BIOS-level access? What could possibly go wrong?

Researchers are warning about the risks posed by a low-cost device that can give insiders and hackers unusually broad powers in compromising networks.

The devices, which typically sell for $30 to $100, are known as IP KVMs. Administrators often use them to remotely access machines on networks. The devices, not much bigger than a deck of cards, allow the machines to be accessed at the BIOS/UEFI level, the firmware that runs before the loading of the operating system.

This provides power and convenience to admins, but in the wrong hands, the capabilities can often torpedo what might otherwise be a secure network. Risks are posed when the devices—which are exposed to the Internet—are deployed with weak security configurations or surreptitiously connected to by insiders. Firmware vulnerabilities also leave them open to remote takeover.

Read full article

Comments

Source: Ars Technica

Share this article

Related Articles

The Download: the North Pole’s future and humanoid data
2026Apr 30

The Download: the North Pole’s future and humanoid data

This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. Digging for clues about the North Pole’s past In t

Article5 min read
Read More
The logic of the racist Supreme Court isn’t adding up
2026Apr 30

The logic of the racist Supreme Court isn’t adding up

Close watchers of the Supreme Court knew that the conservative supermajority was about to murder what was left of the Voting Rights Act. Wednesday's decision in Louisiana v. Callais took down Section

Article1 min read
Read More
Congress keeps kicking surveillance reform down the road
2026Apr 30

Congress keeps kicking surveillance reform down the road

Congress has reauthorized Section 702 of the Foreign Intelligence Surveillance Act - but only for another 45 days. The extension is meant to give legislators more time to negotiate reforms to the cont

Article1 min read
Read More