Skip to main content

Vendor/product archive

kerlink / keros CVEs

Beta · best-effort

3 CVEs tagged to kerlink / keros0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-39148

Published Dec 1, 2025

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root wh…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32388

Published Dec 1, 2025

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32384

Published Dec 1, 2025

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1