ZeroHour

CVE-2025-56007

CVSS 3.1
6.5 medium
EPSS
<1%p25
Published
()
Modified
Description

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

Vendors
keenetic
Products
keeneticos
Weakness
CWE-93
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.