The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kerlink
Kerlink keros |
|
| Vendors & Products |
Kerlink
Kerlink keros |
Mon, 01 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Mon, 01 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-01T19:25:53.069Z
Reserved: 2024-06-21T00:00:00.000Z
Link: CVE-2024-39148
Updated: 2025-12-01T19:25:13.577Z
Status : Received
Published: 2025-12-01T16:15:49.603
Modified: 2025-12-01T20:15:48.617
Link: CVE-2024-39148
No data.