Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.
References
| Link | Resource |
|---|---|
| https://keenetic.com/ | Product |
| https://keenetic.com/global/security#october-2025-web-api-vulnerabilities | Vendor Advisory |
Configurations
History
04 Nov 2025, 13:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:keenetic:keeneticos:*:*:*:*:*:*:*:* | |
| First Time |
Keenetic
Keenetic keeneticos |
|
| References | () https://keenetic.com/ - Product | |
| References | () https://keenetic.com/global/security#october-2025-web-api-vulnerabilities - Vendor Advisory |
23 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CWE | CWE-79 |
23 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-23 15:15
Updated : 2025-11-04 13:09
NVD link : CVE-2025-56008
Mitre link : CVE-2025-56008
CVE.ORG link : CVE-2025-56008
JSON object : View
Products Affected
keenetic
- keeneticos
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
