Опубликовано: 17 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.5
Описание
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-32292
- https://dl.gl-inet.com/release/kvm/release/RM1/1.7.2
- https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-32292
Связанные уязвимости
CVSS3: 7.5
nvd
28 дней назад
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.