Unauthenticated Access Vulnerability in GL-iNet Comet KVM
CVE-2026-32291

7HIGH

Key Information:

Vendor

Gl-inet

Status
Vendor
CVE Published:
17 March 2026

What is CVE-2026-32291?

The GL-iNet Comet KVM (GL-RM1) is exposed to an unauthenticated access vulnerability through its UART serial console. Attackers with physical access to the device can connect to the UART pins without any authentication, potentially gaining full access to the system. This type of vulnerability poses a significant risk, especially in environments where physical security cannot be guaranteed. Proper safeguards should be implemented to restrict unauthorized physical access.

Affected Version(s)

Comet KVM 0 < 1.8.2

Comet KVM 1.8.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reynaldo Vasquez Garcia, Eclypsium
.