Hackers are attempting to exploit CVE-2024-52875 , a critical CRLF injection flaw that allows 1-click remote code execution (RCE) attacks on the GFI KerioControl firewall product .
See also: RCE vulnerability in Kerio Control allows root access to firewall

KerioControl is a network security solution designed for small and medium-sized businesses that combines firewall, VPN, bandwidth management, reporting and monitoring, traffic filtering, AV protection, and intrusion prevention.
On December 16, 2024, security researcher Egidio Romano (EgiX) published a detailed description of CVE-2024-52875, showing how a seemingly low-severity HTTP response splitting issue could escalate to a 1-click RCE.
The flaw, which affects KerioControl versions 9.2.5 to 9.4.5, is due to improper sanitization of line feed (LF) characters in the "dest" parameter, allowing manipulation of the HTTP header and response via injected payloads. Malicious JavaScript injected into the responses is executed in the victim's browser, leading to cookie or CSRF token extraction.
See also: WordPress: Critical vulnerabilities in Spam protection, Anti-Spam, FireWall plugin
An attacker could use the CSRF token of a authenticated admin user to upload a malicious .IMG file containing a root-level shell script, leveraging Kerio's upgrade feature, which opens a reverse shell for the attacker.

Yesterday, threat scanning platform Greynoise detected exploit attempts targeting CVE-2024-52875 from four distinct IP addresses, likely using the PoC exploit code presented by Romano. The activity is marked as “malicious” by the threat monitoring platform, indicating that the exploit are attributed to threat actors rather than researchers investigating systems.
If a patch for the flaw is not currently possible, administrators should restrict access to the KerioControl web management interface to trusted IP addresses and disable public access to the '/admin' and '/noauth' via firewall rules.
See also: Zyxel firewall vulnerability exploited in Ransomware attacks
A firewall flaw refers to a vulnerability or weakness in the design, configuration, or implementation of a firewall that could be exploited by attackers. Such flaws could allow unauthorized access to networks, bypass security restrictions, or leak sensitive information. Common causes of firewall flaws include outdated software, misconfigurations, or failure to apply necessary patches. Identifying and addressing these weaknesses is crucial to maintaining strong network security and preventing potential cyber threats.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
