HomeSecurityOver 12,000 KerioControl firewalls exposed to RCE flaw

Over 12,000 KerioControl firewalls exposed to RCE flaw

More than 12,000 GFI KerioControl firewalls are exposed to a serious vulnerability , which has been registered as CVE-2024-52875.

See also: Voyager management package is vulnerable to RCE flaw

KerioControl RCE

KerioControl is a comprehensive network security solution designed specifically for small and medium-sized businesses. It offers advanced featuressuch as VPN, bandwidth management, analytical reporting and monitoring, traffic filtering, antivirus (AV) protection, and intrusion prevention. The specific flaw was discovered in mid-December by security researcher Egidio Romano (EgiX), who demonstrated the vulnerability to dangerous RCE attacks with a single click.

GFI Software released a security update to address the issue in version 9.4.5 Patch 1 on December 19, 2024. However, three weeks later, according to Censys , more than 23,800 systems remained vulnerable.

Early last month, Greynoise announced that it had detected active exploit attempts using proof-of-concept (PoC) exploit . These attempts were aimed at stealing CSRF administrative tokens, raising serious security concerns.

See also: PoC Exploit released for RCE Apache Struts vulnerability

Despite the warning of active exploitation, threat monitoring service The Shadowserver Foundation reports that it now identifies 12,229 KerioControl firewalls vulnerable to attacks exploiting the RCE vulnerability.

Over 12,000 KerioControl firewalls exposed to RCE flaw

Most of these firewalls are located in countries such as Iran, the United States, Italy, Germany, Russia, Kazakhstan, Uzbekistan, France, Brazil, and India.

With the publication of the Proof of Concept (PoC) for CVE-2024-52875, the exploitation requirements have been significantly reduced. This makes it possible for even inexperienced hackers to engage in malicious activities, increasing the risk of attacks.

If you have not yet installed the latest security update, it is recommended that you proceed to install KerioControl version 9.4.5 (Patch 2), which was released on January 31, 2025 to prevent exploitation of the RCE flaw. This release includes significant security improvements to strengthen your protection.

See also: Hackers exploit KerioControl flaw to steal credentials

Remote code execution is one of the most critical security risks for systems. It typically exploits weaknesses in software, allowing an attacker to remotely execute malicious code without authorization. The consequences of this vulnerability can include compromising confidential data, taking control of the system, or even disrupting operations. Addressing it requires rapid detection, continuous software updates, and implementing safeguards such as firewalls and good code review practices.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS