PT-2025-43520 · Unknown · Keeneticos

CVE-2025-56007

·

Published

2025-10-01

·

Updated

2026-05-20

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions KeeneticOS versions prior to 4.3
Description A CRLF-injection flaw exists in KeeneticOS prior to version 4.3. This issue is present at the /auth API endpoint and could allow attackers to gain control of the device. Exploitation involves adding additional users with full permissions by tricking a victim into opening a malicious page. The auth API endpoint is vulnerable to this injection.
Recommendations Update KeeneticOS to version 4.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14513
CVE-2025-56007

Affected Products

Keeneticos