Filtered by vendor Keenetic Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-56007 1 Keenetic 1 Keeneticos 2025-10-24 6.5 Medium
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.
CVE-2025-56009 1 Keenetic 1 Keeneticos 2025-10-24 5.3 Medium
Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.
CVE-2025-56008 1 Keenetic 1 Keeneticos 2025-10-24 6.1 Medium
Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.