Home

Description

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

PUBLISHED Reserved 2024-06-21 | Published 2025-12-01 | Updated 2025-12-01 | Assigner mitre

References

keros.docs.kerlink.com/security/security_advisories_kerOS5

www.bdosecurity.de/en-gb/advisories/cve-2024-39148

cve.org (CVE-2024-39148)

nvd.nist.gov (CVE-2024-39148)

Download JSON