Use GitHub's private vulnerability reporting for this repository: open the "Security" tab on aethrox/keencli, then "Report a vulnerability". This creates a private advisory visible only to the maintainer until a fix is ready.
In scope: anything that could leak router credentials, API keys, or masked/unmasked diagnostic data (IP, MAC, SSID); authentication bypass against the router; or unsafe handling of data sent to OpenRouter.
Out of scope: vulnerabilities in the Keenetic router firmware itself, or in third-party services (OpenRouter) this project talks to.
This is a solo-maintained project. There is no guaranteed response time, but reports are triaged as they come in and a fix or mitigation is prioritized over new features.