Home

Description

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

PUBLISHED Reserved 2025-08-16 | Published 2025-10-23 | Updated 2025-10-23 | Assigner mitre

References

keenetic.com/

keenetic.com/global/security

cve.org (CVE-2025-56007)

nvd.nist.gov (CVE-2025-56007)

Download JSON