CVE-2026-32290: GL-iNet Comet (GL-RM1) KVM insufficient firmware verification
The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32290?
CVE-2026-32290 is rated as a high-severity vulnerability due to its potential to allow attackers to deploy compromised firmware.
How do I fix CVE-2026-32290?
To mitigate CVE-2026-32290, ensure that firmware is obtained from trusted sources and consider applying security updates from the vendor promptly.
Who is affected by CVE-2026-32290?
CVE-2026-32290 affects users of the GL-iNet Comet (GL-RM1) KVM that do not implement sufficient firmware verification.
What could an attacker do with CVE-2026-32290?
An attacker could exploit CVE-2026-32290 to upload malicious firmware, compromising device integrity and potentially gaining unauthorized access to networks.
Is there a workaround for CVE-2026-32290?
Currently, the best workaround for CVE-2026-32290 is to avoid using unverified firmware updates on the affected GL-iNet Comet (GL-RM1) device.