CVE-2025-56007
MEDIUMKeeneticOS <4.3 - Command Injection
Title source: llmDescription
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.
Scores
CVSS v3
6.5
EPSS
0.0007
EPSS Percentile
22.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-93
Status
published
Affected Products (1)
keenetic/keeneticos
< 4.3
Timeline
Published
Oct 23, 2025
Tracked Since
Feb 18, 2026