Security Research

CVE-2024-52875 Kerio Control CRLF Injection to 1-click RCE: silent firewall takeover

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier panel with copper-orange CRLF flow piercing a firewall

The Kerio Control firewall’s web admin interface does not filter CRLF characters. An attacker crafts a malicious link, lures the admin to click, and gets a shell on the firewall with 1-click.

Unlock to view this content.