Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.
References
Configurations
History
20 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Nov 2025, 13:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:keenetic:keeneticos:*:*:*:*:*:*:*:* | |
| First Time |
Keenetic keeneticos
Keenetic |
|
| References | () https://keenetic.com/ - Product | |
| References | () https://keenetic.com/global/security#october-2025-web-api-vulnerabilities - Vendor Advisory |
23 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| CWE | CWE-79 |
23 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-23 15:15
Updated : 2026-05-20 20:16
NVD link : CVE-2025-56008
Mitre link : CVE-2025-56008
CVE.ORG link : CVE-2025-56008
JSON object : View
Products Affected
keenetic
- keeneticos
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
