Vulnerability Details CVE-2026-32290
The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.6%
CVSS Severity
CVSS v3 Score 4.7
Products affected by CVE-2026-32290
-
cpe:2.3:h:gl-inet:comet_gl-rm1:*
-
cpe:2.3:o:gl-inet:comet_gl-rm1_firmware:*