CVE-2026-32294 affects JetKVM versions prior to 0.5.4, stemming from a lack of proper authenticity verification for downloaded firmware files, which allows an attacker-in-the-middle or compromised update server to inject malicious firmware by altering its SHA256 hash. This vulnerability carries a CVSS score of 4.7 (Medium), requiring local access or user interaction and high attack complexity, with potential for high integrity impact through the installation of unauthorized firmware. Currently, there is no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.3CPE matchmatch criteria | cpe:2.3:a:jetkvm:kvm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.