CVE-2026-32292: GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32292?
CVE-2026-32292 has been classified as a high severity vulnerability due to its potential to allow brute-force attacks on login credentials.
How do I fix CVE-2026-32292?
To mitigate CVE-2026-32292, implement strong password policies and consider using additional security measures such as intrusion detection systems.
What impact does CVE-2026-32292 have on my system?
CVE-2026-32292 allows attackers to perform unlimited login attempts, potentially gaining unauthorized access to the GL-iNet Comet (GL-RM1) KVM.
Which devices are affected by CVE-2026-32292?
CVE-2026-32292 specifically affects the GL-iNet Comet (GL-RM1) KVM web interface.
Is there a workaround for CVE-2026-32292?
A temporary workaround for CVE-2026-32292 is to restrict access to the web interface through a firewall or by using a VPN.