CVE-2024-32384: Kerlink Keros

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.

Affected products

  • Kerlink Keros: from 5.0, before 5.10 (fixed in 5.10)

Published 2025-12-01. Last modified 2026-06-17.