CVE-2026-32298

Publication date

2026-03-17 17:21:56

Family

cisa-cg

State

PUBLISHED

Description

The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the cfg.lua script, allowing an authenticated attacker to execute OS-level commands.