CVE-2025-56007
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://keenetic.com/global/security#october-2025-web-api-vulnerabilities
References
CWEs
CWE-93
Verify integrity in audit chain (admin only). AS-IS.