← Retour aux CVEs
CVE-2025-34071
CRITICAL9.8
Description
A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgrade mechanism accepts unsigned .img files, which can be modified to include malicious scripts within the upgrade.sh or disk image components. These modified upgrade images are not validated for authenticity or integrity, and are executed by the system post-upload, enabling root access.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie7/2/2025
Derniere modification9/17/2025
Sourcenvd
Observations honeypot0
Produits affectes
gfi:kerio_control
Faiblesses (CWE)
CWE-306
References
https://ssd-disclosure.com/ssd-advisory-kerio-control-authentication-bypass-and-rce/(disclosure@vulncheck.com)
https://vulncheck.com/advisories/gfi-kerio-control-auth-bypass-rce(disclosure@vulncheck.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.