PT-2026-25918 · Sipeed · Sipeed Nanokvm

·

CVE-2026-32296

·

Publicado

2026-03-17

·

Atualizado

2026-03-18

CVSS v4.0

8.8

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sipeed NanoKVM versions prior to 2.3.1
Description Sipeed NanoKVM exposes a Wi-Fi configuration endpoint without appropriate security measures. An unauthenticated attacker with network access can modify the saved Wi-Fi network configuration to one of their choosing. Additionally, an attacker can create a request to deplete system memory and terminate the KVM process. The vulnerable endpoint is a Wi-Fi configuration endpoint. The network configuration can be altered by an attacker.
Recommendations Update Sipeed NanoKVM to version 2.3.1 or later.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32296

Produtos afetados

Sipeed Nanokvm