PT-2025-43520 · Unknown · Keeneticos

Published

2025-10-01

·

Updated

2026-05-20

·

CVE-2025-56007

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions KeeneticOS versions prior to 4.3
Description A CRLF-injection flaw exists in KeeneticOS prior to version 4.3. This issue is present at the /auth API endpoint and could allow attackers to gain control of the device. Exploitation involves adding additional users with full permissions by tricking a victim into opening a malicious page. The auth API endpoint is vulnerable to this injection.
Recommendations Update KeeneticOS to version 4.3 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-14513
CVE-2025-56007

Affected Products

Keeneticos