CVE-2026-32298
The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the ‘cfg.lua’ script, allowing an authenticated attacker to execute OS-level commands.
More information : https://eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network/
