
CVE-2026-32292 The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials. https://www.cve.org/CVERecord?id=CVE-2026-32292
Post summary
CVE-2026-32292 reveals that the GL‑iNet Comet’s KVM web interface does not throttle login requests, making it vulnerable to brute‑force credential guessing.


