S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 6, 2025

CVE-2024-52875 Scanner

CVE-2024-52875 Scanner - CRLF Injection vulnerability in Kerio Control

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-52875
8.8
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Kerio Controlby GFI
9.2.5
Updated Aug 22, 2026View on NVD →
Detail

Kerio Control is an all-in-one unified threat management solution used by small and medium-sized businesses for firewall protection, VPN support, and network management. It is widely deployed in enterprise environments to ensure secure connectivity and mitigate cyber threats. The software provides centralized security management and is critical for maintaining secure communication networks.

CRLF Injection is a type of vulnerability where an attacker injects malicious CRLF (Carriage Return Line Feed) sequences into HTTP headers. This allows attackers to manipulate HTTP responses, leading to HTTP response splitting and header injection. It can potentially enable malicious payloads or redirect victims to malicious websites.

The vulnerability exists in specific endpoints of Kerio Control, such as `/nonauth/guestConfirm.cs` and `/nonauth/addCertException.cs`. These endpoints fail to sanitize input adequately, enabling the injection of CRLF sequences. Attackers can exploit this flaw to modify HTTP headers or inject malicious content into responses.

If exploited, this vulnerability can lead to session hijacking, phishing attacks, or unauthorized content injection. It could also allow attackers to manipulate browser behavior or exploit trust between the client and server. This could result in data breaches or compromise of user sessions.

REFERENCES

Solution Advice
  • Update to the latest version of Kerio Control to patch the vulnerability.
  • Implement input validation and encoding to prevent injection attacks.
  • Configure security headers such as Content Security Policy (CSP) to mitigate exploitation risks.
  • Regularly audit and monitor application logs to detect abnormal activities.
  • Conduct regular security assessments to identify and fix vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.