Beveiligingsadvies

CVE-2026-32290

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-17 17:18:14
Laatst bijgewerkt 2026-03-23 19:34:09
Toegewezen door cisa-cg
CVSS-score 7.0
Status PUBLISHED

Beschrijving

The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.