Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.
References
| Link | Resource |
|---|---|
| https://keenetic.com/ | Product |
| https://keenetic.com/global/security#october-2025-web-api-vulnerabilities | Vendor Advisory |
Configurations
History
04 Nov 2025, 13:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://keenetic.com/ - Product | |
| References | () https://keenetic.com/global/security#october-2025-web-api-vulnerabilities - Vendor Advisory | |
| First Time |
Keenetic keeneticos
Keenetic |
|
| CPE | cpe:2.3:o:keenetic:keeneticos:*:*:*:*:*:*:*:* |
Information
Published : 2025-10-23 15:15
Updated : 2025-11-04 13:09
NVD link : CVE-2025-56008
Mitre link : CVE-2025-56008
CVE.ORG link : CVE-2025-56008
JSON object : View
Products Affected
keenetic
- keeneticos
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
