CVE-2026-32291
EUVD-2026-1260017.03.2026, 18:16
The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gl-inet | comet_gl-rm1_firmware | 𝑥 < 1.8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References