The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-17 18:16
Updated : 2026-03-23 20:16
NVD link : CVE-2026-32291
Mitre link : CVE-2026-32291
CVE.ORG link : CVE-2026-32291
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
