Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-34071


A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgrade mechanism accepts unsigned .img files, which can be modified to include malicious scripts within the upgrade.sh or disk image components. These modified upgrade images are not validated for authenticity or integrity, and are executed by the system post-upload, enabling root access.


Published

2025-07-02T14:15:24.667

Last Modified

2025-09-17T13:41:43.400

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gfi kerio_control 9.4.5 Yes

References