Unauthenticated Access Vulnerability in GL-iNet Comet KVM
CVE-2026-32291
7HIGH
What is CVE-2026-32291?
The GL-iNet Comet KVM (GL-RM1) is exposed to an unauthenticated access vulnerability through its UART serial console. Attackers with physical access to the device can connect to the UART pins without any authentication, potentially gaining full access to the system. This type of vulnerability poses a significant risk, especially in environments where physical security cannot be guaranteed. Proper safeguards should be implemented to restrict unauthorized physical access.
Affected Version(s)
Comet KVM 0 < 1.8.2
Comet KVM 1.8.2
