CVE-2025-56009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
23/10/2025
Last modified:
04/11/2025

Description

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:keenetic:keeneticos:*:*:*:*:*:*:*:* 4.3 (excluding)