CVE-2026-32291: GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console
The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32291?
CVE-2026-32291 is considered a critical vulnerability due to the potential for unauthenticated root access via the UART serial console.
How do I fix CVE-2026-32291?
To mitigate CVE-2026-32291, ensure physical security of the GL-iNet Comet (GL-RM1) device to prevent unauthorized access to the UART pins.
Who is affected by CVE-2026-32291?
CVE-2026-32291 affects users of the GL-iNet Comet (GL-RM1) device that expose their UART serial console without authentication.
What are the implications of CVE-2026-32291?
The implications of CVE-2026-32291 include the risk of attackers gaining full control over the affected device and possibly the entire network.
Is physical access needed for CVE-2026-32291 exploitation?
Yes, exploiting CVE-2026-32291 requires physical access to the GL-iNet Comet (GL-RM1) device to connect to the UART pins.