CVE-2026-32291

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
17/03/2026
Last modified:
27/04/2026

Description

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gl-inet:comet_gl-rm1_firmware:*:*:*:*:*:*:*:* 1.8.2 (excluding)
cpe:2.3:h:gl-inet:comet_gl-rm1:-:*:*:*:*:*:*:*