Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-32388

CVE-2024-32388: Kerlink Keros Auth Bypass Vulnerability

CVE-2024-32388 is an authentication bypass flaw in Kerlink Keros that allows attackers to bypass firewall protections via crafted UDP packets. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2024-32388 Overview

CVE-2024-32388 is a firewall misconfiguration vulnerability in Kerlink devices running KerOS versions prior to 5.12. The flaw allows specially crafted User Datagram Protocol (UDP) packets to bypass firewall filtering rules. Attackers can reach UDP-based services that the firewall should otherwise block. The weakness is classified under CWE-402: Transmission of Private Resources into a New Sphere ('Resource Leak').

The vulnerability affects LoRaWAN gateway devices commonly deployed in industrial Internet of Things (IoT) environments. Successful exploitation exposes internal UDP services to unauthorized network access without requiring authentication or user interaction.

Critical Impact

Remote unauthenticated attackers can bypass firewall protections on Kerlink KerOS devices and interact with UDP services intended to be filtered, potentially exposing management and telemetry interfaces.

Affected Products

  • Kerlink KerOS versions prior to 5.12
  • Kerlink LoRaWAN gateway devices running affected KerOS firmware
  • Embedded IoT gateway deployments using Kerlink platforms

Discovery Timeline

  • 2025-12-01 - CVE-2024-32388 published to the National Vulnerability Database (NVD)
  • 2025-12-23 - Last updated in NVD database

Technical Details for CVE-2024-32388

Vulnerability Analysis

The vulnerability stems from improper firewall rule construction in KerOS firmware prior to version 5.12. The firewall fails to correctly evaluate specially crafted UDP packets against its filtering policy. Packets that should match deny rules are instead forwarded to internal services.

UDP is a connectionless transport protocol, which complicates stateful firewall enforcement compared to Transmission Control Protocol (TCP). Misconfigured rules or incorrect packet inspection logic in the KerOS firewall allow attackers to craft packet headers or fragmentation patterns that evade filtering. The result is unauthorized network access to services bound to UDP ports on the device.

The attack requires no privileges and no user interaction, and it is exploitable across the network. Confidentiality impact is limited to information accessible through the exposed UDP services, with no direct integrity or availability impact described by the vendor.

Root Cause

The root cause is a firewall ruleset or packet-filter logic error in KerOS that fails to properly classify certain UDP packets. According to the Kerlink Security Advisory, the misconfiguration permits packets matching specific UDP characteristics to bypass intended deny rules and reach upstream service handlers.

Attack Vector

The attack vector is network-based with low complexity. An attacker sends crafted UDP datagrams to a target Kerlink gateway across any reachable network path. Because UDP services on embedded gateways may include Simple Network Management Protocol (SNMP), Domain Name System (DNS), Network Time Protocol (NTP), or proprietary management protocols, the exposed surface depends on device configuration.

For technical exploitation details, refer to the BDO Security Advisory for CVE-2024-32388. No public proof-of-concept exploit code is currently available.

Detection Methods for CVE-2024-32388

Indicators of Compromise

  • Unexpected UDP traffic reaching internal Kerlink gateway services from external or untrusted network segments
  • Log entries showing UDP service responses to source addresses that should be blocked by firewall policy
  • Anomalous query volumes or unusual UDP packet patterns directed at LoRaWAN gateway management ports

Detection Strategies

  • Inventory all Kerlink devices and identify firmware versions below KerOS 5.12 using asset management tooling
  • Perform external UDP port scans against gateway public interfaces to verify which services respond despite firewall rules
  • Capture and analyze packet flows at the network perimeter to identify UDP packets that bypass expected filtering

Monitoring Recommendations

  • Monitor network telemetry for unauthorized UDP connections to Kerlink gateway IP addresses
  • Enable logging on upstream network firewalls and Intrusion Detection Systems (IDS) to flag UDP traffic destined for management ports
  • Track configuration drift on Kerlink devices and alert on firmware versions known to be affected

How to Mitigate CVE-2024-32388

Immediate Actions Required

  • Upgrade all Kerlink devices to KerOS version 5.12 or later as the primary remediation
  • Place affected gateways behind a properly configured upstream firewall that filters UDP traffic to management ports
  • Restrict network exposure of Kerlink gateways to trusted management networks and Virtual Private Network (VPN) endpoints only

Patch Information

Kerlink has released KerOS 5.12 containing the corrected firewall configuration. Refer to the Kerlink Security Advisory for download instructions and release notes. Apply firmware updates through the standard KerOS update procedure following the vendor documentation.

Workarounds

  • Deploy network-level access control lists (ACLs) on upstream routers or firewalls to block untrusted UDP traffic before it reaches Kerlink devices
  • Disable any non-essential UDP services on the gateway to minimize exposure until patching is complete
  • Segment Kerlink gateways into dedicated Virtual Local Area Networks (VLANs) with strict ingress filtering
bash
# Example upstream iptables rule to restrict UDP access to a Kerlink gateway
# Replace 10.0.0.10 with the gateway IP and 10.0.0.0/24 with the trusted management subnet
iptables -A FORWARD -p udp -d 10.0.0.10 -s 10.0.0.0/24 -j ACCEPT
iptables -A FORWARD -p udp -d 10.0.0.10 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.