CVE-2024-39148
HIGHKerOS < 5.12 - Unauthenticated Remote Code Execution via Magic URL Validation Flaw
Title source: llmDescription
The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.
References (2)
Core 2
Core References
Third Party Advisory
https://www.bdosecurity.de/en-gb/advisories/cve-2024-39148
Scores
CVSS v3
8.1
EPSS
0.0044
EPSS Percentile
35.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
kerlink/keros
5.0 - 5.12
Published
Dec 01, 2025
Tracked Since
Feb 18, 2026