PT-2025-43522 · Keenetic · Keeneticos

Published

2025-10-01

·

Updated

2026-05-20

·

CVE-2025-56009

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions KeeneticOS versions prior to 4.3
Description A cross site request forgery (CSRF) issue exists in KeeneticOS. The issue is present in the ''/rci'' API endpoint and allows attackers to gain control of the device by adding users with full permissions. This is achieved by tricking a victim into opening a malicious page.
Recommendations Update KeeneticOS to version 4.3 or later.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-14514
CVE-2025-56009

Affected Products

Keeneticos