CVE-2024-32388: Kerlink Keros

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall and access UDP-based services that would otherwise be protected.

Affected products

  • Kerlink Keros: from 5.0, before 5.12 (fixed in 5.12)

Published 2025-12-01. Last modified 2026-06-17.