ZeroHour

CVE-2025-56009

CVSS 3.1
5.3 medium
EPSS
<1%p7
Published
()
Modified
Description

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

Vendors
keenetic
Products
keeneticos
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.