Junglewise Threat Intelligence

CVE-2024-32389: Kerlink KerOS Buffer Overflow in SNMP Update Mechanism

CVE-2024-32389 · Severity: low · CVSS 3.5 · Published 2026-07-16

Technologies: Kerlink KerOS, Kerlink Wirnet iStation 868. Vendors: Kerlink.

Executive brief

A security vulnerability exists in the software powering Kerlink Wirnet iStation IoT gateways. An attacker on the same local network could exploit a flaw in how the device handles update requests to cause memory errors and potentially access sensitive information. This could lead to unauthorized data exposure or impact the stability of the gateway device.

Technical details

A buffer overflow vulnerability exists in Kerlink KerOS versions 4.3.3 and below, specifically within the SNMP update mechanism. The flaw is rooted in improper input validation (CWE-20) when handling URLs provided for update packages. An attacker located on the same adjacent network can provide a specially crafted URL that triggers memory corruption. This can be leveraged to achieve limited information disclosure. The vendor has indicated that KerOS 4 and 5 are end-of-life and recommends migrating to KerOS 6, which is not affected.

Affected products

  • Kerlink KerOS <= 4.3.3
  • Kerlink Wirnet iStation 868 <= 4.3.3

Timeline

  • 2024-03-19: disclosed: Vulnerability reported to vendor
  • 2024-03-29: other: Vendor confirmed vulnerability
  • 2025-09-06: other: Vendor declared KerOS 4 End-of-Life (EOL)
  • 2026-05-27: advisory: Public disclosure by BDO Security

References

Related threats