CVE-2025-56007

MEDIUM

KeeneticOS <4.3 - Command Injection

Title source: llm

Description

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 22.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-93
Status published

Affected Products (1)

keenetic/keeneticos < 4.3

Timeline

Published Oct 23, 2025
Tracked Since Feb 18, 2026