Keenetic manufactures embedded networking and routing devices centered on its KeeneticOS firmware, presenting a narrowly scoped but internet-facing product line. The vendor's disclosed vulnerabilities cluster around web-interface weaknesses including cross-site request forgery, CRLF injection, and cross-site scripting that reflect the attack surface of browser-accessible management interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keenetic over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56007MEDIUM CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to | Oct 23, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-56008MEDIUM Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional us | Oct 23, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-56009MEDIUM Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permi | Oct 23, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keenetic.
Media articles that mention a CVE ID that affects a product developed by Keenetic — matched by CVE ID, not by vendor name.