Skip to content

Conversation

@notdenied
Copy link

Updates

  • Affected products
  • CVSS v3
  • References
  • Summary

Comments
I am the author of this CVE. :)

Added title, published a small writeup, some other minor changes.

Not sure if I have to check "Integrity" and "Availability" while the impact is router takeover (RCE) so skip them for now.

@github-actions github-actions bot changed the base branch from main to notdenied/advisory-improvement-6350 October 26, 2025 10:56
@notdenied
Copy link
Author

Also, if it is possible, may you add me (Andrey Ryzhov) to the credits section, please? This is my CVE (if you need a proof, feel free to contact me).
I've already contacted MITRE for this addition, but also want to add it on Github.

@shelbyc
Copy link
Contributor

shelbyc commented Oct 27, 2025

Hi @notdenied, I can't review this advisory (and therefore can't add credit) because I can't find anything about KeeneticOS in Pub or any of the GitHub Advisory Database's supported ecosystems. From what I can see at https://github.com/orgs/keenetic/repositories?type=all, the vast majority of KeeneticOS repos are dominated by C. Does CVE-2025-56007 affect any packages in a supported ecosystem?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants