CVE-2024-52875: Kerio Control v9.2.5 - CRLF Injection

HoneyLabs honeypots recorded 4 probes matching CVE-2024-52875 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /nonauth/guestConfirm.cs
  • /nonauth/expiration.cs
  • /nonauth/addCertException.cs

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2144Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited41

Captured requests

  • /nonauth/guestConfirm.cs?dest=VGVzdA0KQ1JMRjo%3d
  • /nonauth/guestConfirm.cs?dest=Cgo8c2NyaXB0PmFsZXJ0KGRvY3VtZW50LmRvbWFpbik8L3NjcmlwdD4%3d
  • /nonauth/expiration.cs?dest=VGVzdA0KQ1JMRjo%3d
  • /nonauth/addCertException.cs?dest=VGVzdA0KQ1JMRjo%3d

CVE report

CVE report

Open a specific CVE from the CVE tracker.