gfi News Articles
Recent news articles refferecing the vendors vulnerabilities.
Over 12,000 KerioControl firewalls exposed to exploited RCE flaw
Over twelve thousand GFI KerioControl firewall instances are exposed to a critical remote code execution vulnerability tracked as CVE-2024-52875.

Ivanti patches actively exploited zero-day.
Attackers target one-click vulnerability affecting GFI KerioControl firewalls. Palo Alto Networks patches vulnerabilities affecting its Expedition migration tool.

Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF Injection
CVE-2024-52875, a critical RCE flaw in GFI KerioControl firewalls, allows HTTP response splitting and exploits over 23,800 internet-exposed instances
Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens
Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in GFI KerioControl firewall product.
7 Years Old RCE Vulnerability Addressed In Kerio Control
Exploiting the Kerio Control vulnerability could allow root access to the target firewall, compromising the firm's network structure.

1-Click RCE Attack in Kerio Control UTM Let Attackers Gain Root Access To the Firewall
Researchers have identified a critical set of vulnerabilities in Kerio Control, a widely used Unified Threat Management (UTM) solution developed by GFI Software.