HarborGuard / CVE
Back to search
HIGHCVE-2026-32291Published Modified CNA cisa-cg

CVE-2026-32291: GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.

Metrics

CVSS v4.0
7.0
Severity
HIGH
Fixed in
1.8.2
Affected Products
1

Fix available

1.8.2
Patch commits
Affected packages
  • GL-iNet / Comet KVM
    < 1.8.2 (from 0)
    Fixed in 1.8.2
CVSS Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References