Authentication Bypass in GFI Kerio Control by GFI
CVE-2025-34070
What is CVE-2025-34070?
A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows remote attackers to perform privileged operations without authentication. The GFIAgent service exposes HTTP services on ports 7995 and 7996, leading to an authentication bypass. Through the /proxy handler on port 7996, attackers can perform arbitrary forwarding to sensitive administrative endpoints by leveraging a retrieved Appliance UUID from port 7995. This flaw provides unauthenticated access to critical administrative APIs, posing significant security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kerio Control 9.4.5
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
