Skip to content

[GHSA-82pw-p4cc-5522] Cross site scripting (XSS) vulnerability in KeeneticOS...#6351

Closed
notdenied wants to merge 1 commit intonotdenied/advisory-improvement-6351from
notdenied-GHSA-82pw-p4cc-5522
Closed

[GHSA-82pw-p4cc-5522] Cross site scripting (XSS) vulnerability in KeeneticOS...#6351
notdenied wants to merge 1 commit intonotdenied/advisory-improvement-6351from
notdenied-GHSA-82pw-p4cc-5522

Conversation

@notdenied
Copy link

Updates

  • Affected products
  • CVSS v3
  • References
  • Summary

Comments
I am the author of this CVE. :)

Added title, published a small writeup, some other minor changes.

Not sure if I have to check "Integrity" and "Availability" while the impact is router takeover (RCE) so skip them for now.

Also, if it is possible, may you add me (Andrey Ryzhov) to the credits section, please? This is my CVE (if you need a proof, feel free to contact me).
I've already contacted MITRE for this addition, but also want to add it on Github.

@github-actions github-actions bot changed the base branch from main to notdenied/advisory-improvement-6351 October 26, 2025 11:42
@notdenied
Copy link
Author

Affected versions are <= 4.2, NOT 4.3, it is my typo. Unfortunately, I can't change the file in this merge request by myself.

@shelbyc
Copy link
Contributor

shelbyc commented Oct 27, 2025

Hi @notdenied, similar to #6350, I can't find KeeneticOS in Pub or any other supported ecosystem and therefore can't review the advisory. Does CVE-2025-56008 affect any packages in a supported ecosystem?

@notdenied
Copy link
Author

Hi, @shelbyc! As in #6350, unfortunately I can't suggest a better candidate for a project than https://github.com/keenetic/keenetic-sdk. This issue is also in web panel, which is a part of closed-source OS.

@advisory-database advisory-database bot closed this Nov 3, 2025
@github-actions github-actions bot deleted the notdenied-GHSA-82pw-p4cc-5522 branch November 3, 2025 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants