# CVE-2024-52875

## Summary

- **CVE ID:** CVE-2024-52875
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** CWE-113
- **Published:** Jan 31, 2025
- **Last Modified:** Mar 13, 2026

## Description

An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.

## Affected Products

- GFI — Kerio Control (9.2.5)

## References

- [CNA](https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875)
- [CVE](http://seclists.org/fulldisclosure/2024/Dec/15)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 29.56%
- **EPSS Percentile:** 98.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._