VendorsGFIkerio_controlall versions
Vulnerabilities

GFI Kerio Control

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-34070
GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces
Published 2025-07-02 · Analyzed
10.0EPSS 0.007
CVE-2025-34071
GFI Kerio Control Unsigned System Image Upload Root Code Execution
Published 2025-07-02 · Analyzed
9.8EPSS 0.008
CVE-2025-34069
GFI Kerio Control GFIAgent Authentication Bypass via Proxy Forwarding
Published 2025-07-02 · Analyzed
9.8EPSS 0.007
CVE-2024-52875
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.
Published 2025-01-31 · Analyzed
8.8EPSS 0.296
CVE-2019-16414
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure&NTLM= URI.
Published 2019-09-30 · Modified
6.1EPSS 0.016