PT-2026-25916 · Jetkvm · Jetkvm
Paul Asadoorian
·
Published
2026-03-17
·
Updated
2026-03-17
·
CVE-2026-32294
CVSS v3.1
4.7
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding SHA256 hash to pass verification.
Fix
Improper Verification of Cryptographic Signature
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetkvm