CVE-2026-32292

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
17/03/2026
Last modified:
27/04/2026

Description

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gl-inet:comet_gl-rm1_firmware:*:*:*:*:*:*:*:* 1.7.2 (excluding)
cpe:2.3:h:gl-inet:comet_gl-rm1:-:*:*:*:*:*:*:*