PT-2025-43520 · Unknown · Keeneticos
Published
2025-10-01
·
Updated
2026-05-20
·
CVE-2025-56007
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
KeeneticOS versions prior to 4.3
Description
A CRLF-injection flaw exists in KeeneticOS prior to version 4.3. This issue is present at the
/auth API endpoint and could allow attackers to gain control of the device. Exploitation involves adding additional users with full permissions by tricking a victim into opening a malicious page. The auth API endpoint is vulnerable to this injection.Recommendations
Update KeeneticOS to version 4.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keeneticos