GL-iNet Comet KVM Insufficient Firmware Verification Vulnerability

Vulnerability

A vulnerability exists in the GL-iNet Comet KVM (model GL-RM1) due to inadequate verification of the authenticity of uploaded firmware files. This flaw allows an attacker-in-the-middle or a compromised update server to alter the firmware and its corresponding MD5 hash, enabling the modified firmware to pass verification. The lack of proper validation creates a significant security risk, as the device may accept tampered firmware as legitimate.

Impact

Exploitation of this vulnerability allows for the installation of malicious firmware that could be used to compromise the KVM device. A compromised KVM can provide attackers with physical-like access to all connected machines, enabling them to control the systems via keyboard and mouse emulation, access BIOS settings, and boot from removable media to bypass OS-level security controls.

Remediation

GL-iNet has no planned fix for this vulnerability.

Added: Mar 17, 2026, 6:26 PM
Updated: Mar 17, 2026, 6:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.1
remediation
0.0
relevance
4.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.