CVE-2025-56009

MEDIUM

KeeneticOS <4.3 - CSRF

Title source: llm

Description

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-352
Status published

Affected Products (1)

keenetic/keeneticos < 4.3

Timeline

Published Oct 23, 2025
Tracked Since Feb 18, 2026