Brute Force Vulnerability in GL-iNet Comet KVM Web Interface
CVE-2026-32292

9.3CRITICAL

Key Information:

Vendor

Gl-inet

Status
Vendor
CVE Published:
17 March 2026

What is CVE-2026-32292?

The GL-iNet Comet (GL-RM1) KVM web interface is exposed to unauthorized access due to a lack of safeguards against brute-force login attempts. This flaw allows malicious actors to exploit the system by continuously guessing login credentials, potentially compromising sensitive configurations and overall network security.

Affected Version(s)

Comet KVM 0 < 1.7.2

Comet KVM 1.7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reynaldo Vasquez Garcia, Eclypsium
.