CVE-2025-56008: Keenetic Keeneticos

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.

Affected products

  • Keenetic Keeneticos: before 4.3 (fixed in 4.3)

Published 2025-10-23. Last modified 2026-06-17.