CVE-2025-34070 - CVE House
Back to Database
Status published Critical CVE-2025-34070

GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces

Vulnerability Description

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34070

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • z3er01 of zeronvll
  • SSD Secure Disclosure

Affected Vendor

GFI Software

View all reports →

Affected Software

Kerio Control
Vulnerable Versions:
9.4.5

Timeline

Official Publish: July 2nd, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)