CVE-2025-56008 Details
Description
Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions.
A cross-site scripting (XSS) vulnerability exists in KeeneticOS versions prior to 4.3, specifically on the Wireless ISP configuration page. This vulnerability allows attackers in close proximity to the router to execute malicious scripts by broadcasting a specially crafted SSID. When the script is executed, it can take over the device by adding new users with full permissions.
Users are advised to upgrade to KeeneticOS 4.3, which addresses this vulnerability. Firmware updates can be done through the device's web interface or the Keenetic mobile app.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| keenetic keeneticos | < 4.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | CVE Modified | [email protected] |
| Nov 4, 2025 | Initial Analysis | [email protected] |
| Oct 23, 2025 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | New CVE Received | [email protected] |