ZeroNvll

Navigation

  • Home
  • WhoAmI
  • Research
  • CVE
  • Contacts

Navigation

  • Home
  • WhoAmI
  • Research
  • CVE
  • Contacts

Write-ups

Home

Jun 15, 20261 min read

ZeroNvll is an offensive security research hub - application and hardware security, 0day discovery, and exploit development. We break things, prove the break, and publish what survives review.

Latest CVE

KerioControl Auth Bypass and RCE - unauthenticated proxy abuse chained to the update mechanism for root on the appliance. Read the write-up → KerioControl-Auth-Bypass-and-RCE


  • WhoAmIWho I am, my focus areas, and my track record.→
  • ResearchTechnical write-ups, exploit development, and reverse engineering.→
  • CVEDisclosed vulnerabilities, grouped by vendor and product.→
  • ContactsEmail, PGP key, and bug bounty profiles.→

Latest write-ups

  • KerioControl Auth Bypass and RCE

    Jun 25, 2025

    An unauthenticated attacker reaches Kerio Control's internal GFIAgent service through the default non-transparent proxy, bypassing authentication, then abuses the software update mechanism to upload a modified system image and gain root on the appliance.

    #research#ZD001-KROCNRL#ssd-disclosure
  • ISPConfig Priv-Esc and Code Injection

    Jun 11, 2025

    The analysis of ISPConfig revealed critical design flaws enabling privilege escalation to superadmin and arbitrary PHP code injection.

    #research#ZD002-IPOFG#ssd-disclosure
  • TCL substitution of global parameter values in Gaia Portal

    Nov 15, 2024

    Authenticated Gaia users, at least read-only privilege, can inject code or commands by global variables through HTTP requests.

    #research#cve#checkpoint

Graph View

Contact

contact@zeronvll.com
Download

PGP Public Key - contact@zeronvll.com

Davide Virruso | zeronvll © 2026 - info@zeronvll.com

  • Linkedin
  • Intigriti
  • Hackerone