CVE-2026-32293: GL-iNet Comet (GL-RM1) KVM insufficient certificate validation
The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to serve invalid client and CA certificates. The GL-RM1 will attempt to use the invalid certificates and fail to connect to the legitimate GL-iNet KVM cloud service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32293?
CVE-2026-32293 has a severity rating that indicates a high risk due to its potential for allowing attackers to intercept communications.
How do I fix CVE-2026-32293?
To fix CVE-2026-32293, ensure that the GL-iNet Comet (GL-RM1) KVM properly validates certificates during its connection to the provisioning site.
What are the risks associated with CVE-2026-32293?
The risks associated with CVE-2026-32293 include the potential for man-in-the-middle attacks and unauthorized access to sensitive information.
Who is affected by CVE-2026-32293?
CVE-2026-32293 specifically affects users of the GL-iNet Comet (GL-RM1) KVM device.
What can attackers do with CVE-2026-32293?
Attackers can exploit CVE-2026-32293 to serve invalid client or CA certificates, potentially compromising the security of the connected network.