CVE-2026-32291
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
17/03/2026
Last modified:
18/03/2026
Description
The GL-iNet Comet (GL-RM1) KVM does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.80
Severity 3.x
MEDIUM



