Junglewise Threat Intelligence

CVE-2025-56008: Keenetic KeeneticOS XSS in Wireless ISP page

CVE-2025-56008 · Severity: medium · CVSS 6.1 · Published 2025-10-23

Technologies: Keeneticos. Vendors: Keenetic.

Executive brief

A security vulnerability exists in KeeneticOS, the operating system used in Keenetic network routers. An attacker physically located near the router can broadcast a malicious Wi-Fi network name that, when viewed by an administrator on the router's management page, allows the attacker to take control of the device. This could lead to the creation of unauthorized administrator accounts, giving the attacker full access to the network and user data.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'Wireless ISP' component of KeeneticOS before version 4.3. The vulnerability is triggered when the router scans for nearby Wi-Fi networks and renders their SSIDs on the management web interface without proper sanitization. An attacker within radio range can broadcast malicious SSIDs containing JavaScript payloads. Because SSIDs are limited to 32 characters, an attacker can use multiple beacons to reconstruct and execute a larger payload. Successful exploitation allows an attacker to steal session cookies or use the Web API to add new administrative users with full permissions. The issue is resolved in KeeneticOS version 4.3.

Affected products

  • Keenetic KeeneticOS before 4.3

Timeline

  • 2025-10-23: advisory: Initial advisory published by Keenetic and NVD
  • 2025-10-23: disclosed: Vulnerability details and PoC released by researcher

References

Related threats