« Volver al listado

Gl-inet

Gl-inet Comet Gl-rm1 Firmware: vulnerabilidades y CVE

Gl-inet Comet Gl-rm1 Firmware tiene 4 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses4
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-32293Media (6.3)0.32%—17 mar 2026
The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to…
CVE-2026-32292Crítica (9.3)0.55%—17 mar 2026
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.
CVE-2026-32291Alta (7)0.34%—17 mar 2026
The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.
CVE-2026-32290Alta (7)0.13%—17 mar 2026
The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts1
  2. T1078.001 Default Accounts1
  3. T1091 Replication Through Removable Media1
  4. T1190 Exploit Public-Facing Application1
  5. T1195 Supply Chain Compromise1
  6. T1195.002 Compromise Software Supply Chain1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Gl-inet