Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet comet Gl-rm1
Gl-inet comet Gl-rm1 Firmware |
|
| CPEs | cpe:2.3:h:gl-inet:comet_gl-rm1:-:*:*:*:*:*:*:* cpe:2.3:o:gl-inet:comet_gl-rm1_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gl-inet comet Gl-rm1
Gl-inet comet Gl-rm1 Firmware |
Mon, 23 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GL-iNet Comet (GL-RM1) KVM does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins. | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins. |
| References |
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet
Gl-inet comet Kvm |
|
| Vendors & Products |
Gl-inet
Gl-inet comet Kvm |
Tue, 17 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GL-iNet Comet (GL-RM1) KVM does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins. | |
| Title | GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-03-23T19:34:20.347Z
Reserved: 2026-03-11T18:26:10.038Z
Link: CVE-2026-32291
Updated: 2026-03-17T18:12:31.408Z
Status : Analyzed
Published: 2026-03-17T18:16:16.057
Modified: 2026-04-27T12:36:50.560
Link: CVE-2026-32291
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:49:07Z