CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.Referenceshttps://keenetic.com/https://keenetic.com/global/security#october-2025-web-api-vulnerabilitieshttps://github.com/notdenied/writeups/blob/main/CVE/CVE-2025-56007.md