Brute Force Vulnerability in GL-iNet Comet KVM Web Interface
CVE-2026-32292
9.3CRITICAL
What is CVE-2026-32292?
The GL-iNet Comet (GL-RM1) KVM web interface is exposed to unauthorized access due to a lack of safeguards against brute-force login attempts. This flaw allows malicious actors to exploit the system by continuously guessing login credentials, potentially compromising sensitive configurations and overall network security.
Affected Version(s)
Comet KVM 0 < 1.7.2
Comet KVM 1.7.2
