CVE-2025-56007 Details
Description
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.
A CRLF injection vulnerability has been identified in KeeneticOS versions prior to 4.3, specifically at the '/auth' API endpoint. This vulnerability allows remote attackers to manipulate HTTP headers and inject unauthorized commands. Exploitation involves adding new administrative users, thereby gaining control of the affected device. The attack requires the victim to open a specially crafted page.
Users are advised to upgrade to KeeneticOS 4.3, which addresses this vulnerability. Firmware updates can be applied through the device's web interface or the Keenetic mobile app.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| keenetic keeneticos | < 4.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | CVE Modified | [email protected] |
| Nov 4, 2025 | Initial Analysis | [email protected] |
| Oct 23, 2025 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | New CVE Received | [email protected] |