Critical CVE-2024-52875 Vulnerability Exposes Over 12,000 KerioControl Firewalls to Remote Code Execution Attacks

Listen to this Post

2025-02-10

A recently discovered vulnerability, tracked as CVE-2024-52875, is affecting over twelve thousand KerioControl firewall instances, placing businesses at risk of remote code execution (RCE) attacks. This flaw allows unskilled hackers to exploit the system, potentially compromising network security. Despite a security update from GFI Software, the number of exposed instances remains alarmingly high, making it crucial for users to take immediate action.

Summary:

GFI KerioControl, a popular network security solution used by small and medium-sized businesses, is vulnerable to CVE-2024-52875, which allows for critical remote code execution (RCE). Discovered by Egidio Romano in December 2024, the flaw was demonstrated as a one-click attack vector that could be exploited to take control of the affected systems. GFI released a patch (9.4.5 Patch 1) on December 19, 2024, but data from Censys reveals that more than 23,000 instances were still exposed three weeks later.

Further investigation by Greynoise found active exploitation attempts using Romano’s proof-of-concept (PoC) exploit. The vulnerability targets input passed through the “dest” GET parameter and can result in HTTP Response Splitting and Reflected Cross-Site Scripting (XSS) attacks. This XSS vector, if exploited, could lead to 1-click remote code execution (RCE).

According to The Shadowserver Foundation, over 12,000 KerioControl firewalls remain exposed globally, particularly in countries like Iran, the US, Germany, and India. The PoC is publicly available, making it easier for even inexperienced attackers to exploit the vulnerability. A follow-up patch (version 9.4.5 Patch 2) was released on January 31, 2025, containing additional security fixes. It is strongly recommended that users apply this update to mitigate risks.

What Undercode Says:

The CVE-2024-52875 vulnerability highlights several critical issues in the security posture of KerioControl firewalls, impacting businesses across the globe. The vulnerability’s discovery by Egidio Romano and subsequent PoC exploitation underlines the ease with which unskilled attackers can now compromise systems. The fact that over 12,000 instances are still exposed weeks after the patch was released is a clear indicator of poor patch management practices within organizations.

The vulnerability itself is rooted in improper sanitization of user input, which allows malicious actors to perform HTTP Response Splitting attacks. This failure in input validation opens the door to Reflected XSS and remote code execution—two of the most dangerous attack vectors in modern cybersecurity. What makes this particular vulnerability even more concerning is its simplicity: even unskilled hackers can leverage the publicly available PoC to execute the attack, amplifying the risk of widespread exploitation.

One notable aspect of the CVE-2024-52875 flaw is the low technical barrier required to exploit it. While many cybersecurity vulnerabilities require a certain level of expertise to exploit effectively, this one is accessible to virtually anyone with malicious intent. The existence of an easily exploitable PoC makes it more likely that this issue will continue to see exploitation attempts, especially given the widespread visibility it has garnered through platforms like Greynoise and The Shadowserver Foundation.

The continued exposure of vulnerable instances underscores the importance of timely patching. The patch (9.4.5 Patch 1) released by GFI Software was crucial in addressing the flaw, but it appears that many organizations failed to apply it in a timely manner. As cybersecurity threats evolve, it is crucial for businesses to adopt proactive security measures, including patch management, to reduce the window of vulnerability and protect their networks from emerging threats.

The global distribution of affected systems, with instances in countries such as Iran, the US, Germany, and India, highlights the widespread nature of the issue. This is not an isolated problem—KerioControl users from various regions are at risk, and the vulnerability has become a focal point for cybercriminals looking to exploit exposed systems.

In conclusion, the CVE-2024-52875 vulnerability serves as a stark reminder of the importance of cybersecurity hygiene. The ease with which the flaw can be exploited, combined with the large number of exposed systems, presents a serious risk. Businesses must prioritize the timely application of security updates and remain vigilant in monitoring their network security. The release of Patch 2 should act as a final wake-up call for those who have yet to update their systems. Organizations should also focus on improving their overall security protocols, including user input sanitization, to prevent similar vulnerabilities from emerging in the future.

References:

Reported By: https://www.bleepingcomputer.com/news/security/over-12-000-keriocontrol-firewalls-exposed-to-exploited-rce-flaw/
https://www.reddit.com
Wikipedia: https://www.wikipedia.org
Undercode AI: https://ai.undercodetesting.com

Image Source:

OpenAI: https://craiyon.com
Undercode AI DI v2: https://ai.undercode.helpFeatured Image