CVE-2026-32290
EUVD-2026-1259817.03.2026, 18:16
The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gl-inet | comet_gl-rm1_firmware | 𝑥 < 1.8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References