GL-iNet Comet KVM Insecure Initial Provisioning via Unauthenticated Cloud Connection

Vulnerability

A vulnerability exists in the GL-iNet Comet KVM (GL-RM1) due to improper validation of certificates during the initial provisioning process. When the device boots up, it connects to a GL-iNet cloud service to retrieve client and CA certificates. However, the GL-RM1 does not verify the authenticity of these certificates, leaving it open to man-in-the-middle attacks. An attacker could intercept the connection and provide invalid certificates, which the device would accept without validation. This flaw causes the KVM to fail authentication with the legitimate GL-iNet cloud service, disrupting its functionality.

Impact

Exploitation of this vulnerability allows for a persistent denial-of-service condition, where the KVM fails to connect to the legitimate cloud service, and breaks the chain of trust by accepting fraudulent certificates.

Remediation

This vulnerability has been fixed in GL-iNet Comet KVM version 1.8.1 BETA.

Added: Mar 17, 2026, 6:23 PM
Updated: Mar 17, 2026, 6:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
7.2
remediation
0.0
relevance
4.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.