CVE-2024-39148

HIGH

KerOS < 5.12 - Unauthenticated Remote Code Execution via Magic URL Validation Flaw

Title source: llm
STIX 2.1

Description

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

Scores

CVSS v3 8.1
EPSS 0.0044
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
kerlink/keros 5.0 - 5.12
Published Dec 01, 2025
Tracked Since Feb 18, 2026