Insufficient Firmware Verification in GL-iNet Comet KVM Device
CVE-2026-32290

7HIGH

Key Information:

Vendor

Gl-inet

Status
Vendor
CVE Published:
17 March 2026

What is CVE-2026-32290?

The GL-iNet Comet (GL-RM1) KVM device is vulnerable due to inadequate validation of the authenticity of uploaded firmware files. This weakness allows an attacker to manipulate the firmware alongside its corresponding MD5 hash, potentially leading to unauthorized modifications. Such a flaw can be exploited via man-in-the-middle attacks or through compromised update servers, creating significant security risks for users relying on this device.

Affected Version(s)

Comet KVM 0 < 1.8.2

Comet KVM 1.8.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reynaldo Vasquez Garcia, Eclypsium
.