CVE-2026-32290: Gl-Inet Comet Gl-RM1 Firmware

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.

Affected products

  • Gl-Inet Comet Gl-RM1 Firmware: before 1.8.2 (fixed in 1.8.2)

Published 2026-03-17. Last modified 2026-06-17.