Junglewise Threat Intelligence

CVE-2024-32385: Kerlink KerOS information disclosure via mDNS

CVE-2024-32385 · Severity: medium · CVSS 4.3 · Published 2026-07-16

Technologies: Kerlink KerOS, Kerlink Wirnet iStation 868. Vendors: Kerlink.

Executive brief

Kerlink KerOS, the operating system for industrial IoT gateways like the Wirnet iStation, is affected by an information disclosure vulnerability. An attacker on the same local network can view device-specific identifiers that could be used to gain unauthorized access to management services, including network monitoring tools. This could lead to a compromise of the gateway's configuration or the broader IoT network it manages.

Technical details

An information disclosure vulnerability exists in Kerlink KerOS versions 4.3.3 and below due to the exposure of device-specific data via Multicast DNS (mDNS). An unauthenticated attacker located on the same adjacent network can query mDNS to obtain the 'boardID' and 'revisionID' components. This sensitive information can be leveraged to gain privileged access to management services, such as SNMP. The vendor has stated that KerOS 4 and 5 are end-of-life (EOL) and recommends migrating to KerOS 6, which is not affected by this issue.

Affected products

  • Kerlink KerOS <= 4.3.3
  • Kerlink Wirnet iStation 868 4.3.3_20200803132042

Timeline

  • 2024-03-19: disclosed: Vulnerability reported to Kerlink
  • 2024-03-29: other: Vendor confirmed the vulnerabilities
  • 2025-09-06: other: Vendor informed researcher that KerOS 4 is EOL
  • 2026-05-27: advisory: Public disclosure by BDO Security

References

Related threats