Kerlink's vulnerability profile centers on its Keros IoT gateway and related wireless infrastructure products, with observed weaknesses reflecting the security challenges of embedded network devices handling sensitive telemetry data. The recurring exposure involves cleartext transmission of sensitive information, code injection, improper channel verification, and resource leaks—authentication, encryption, and data-handling issues typical of constrained embedded systems operating in trusted-network environments. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kerlink over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-39148HIGH The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root whe | Dec 1, 2025 | 8.1 | 26 | NO | NO |
CVE-2024-32384HIGH Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in- | Dec 1, 2025 | 7.4 | 24 | NO | NO |
CVE-2024-32388MEDIUM Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall and | Dec 1, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kerlink.
Media articles that mention a CVE ID that affects a product developed by Kerlink — matched by CVE ID, not by vendor name.