CVE-2026-32290: Gl-Inet Comet Gl-RM1 Firmware
Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.
The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.
Affected products
- Gl-Inet Comet Gl-RM1 Firmware: before 1.8.2 (fixed in 1.8.2)
Published 2026-03-17. Last modified 2026-06-17.