Skip to main content

User Manual

Keenetic extender security

Information and instructions to the user

Document ID: KN-3411-CS-INFO-02

Revision: 1.1

Date: April 2026

Manufacturer: Keenetic Limited. Office 2703A, 148 Electric Road, North Point, Hong Kong.

1. Purpose of this document

This document provides the manufacturer’s description of the intended purpose, essential functionalities, security properties, and foreseeable misuse scenarios of the Keenetic Buddy 6 (KN-3411).

2. Product identification and general description

The Keenetic Buddy 6 (KN-3411) is a Wi-Fi range extender designed for residential and SOHO deployments. The product provides wireless network connectivity and extends wired Ethernet networks through IEEE 802.11 wireless technology. It is equipped with a Gigabit Ethernet interface supporting Power over Ethernet (PoE) and, when used with any Keenetic router, allows you to set up a Mesh Wi-Fi System.

3. Intended purpose

The device is intended to operate as a managed wireless range extender within a local IP network. Its primary purpose is to provide secure wireless connectivity for client devices and to extend or create wireless network coverage as part of an existing network infrastructure.

The product is intended for installation in an indoor environment in accordance with the installation instructions and environmental specifications.

4. Security environment

The device operates on KeeneticOS with integrated networking, device management and security functions. The system includes secure software update mechanisms, user authentication, encrypted management interfaces, wireless security functions and diagnostic capabilities. Automatic software update functionality is available through the KeeneticOS update system.

5. Essential functionalities

6. Security properties

Authentication and access control mechanisms are enforced, including mandatory administrator password setup and brute-force protection. Secure-by-default exposure controls restrict external access. Secure administration is supported via encrypted interfaces. The device includes software update security, modern wireless security protocols, segmentation, DNS privacy and logging functions.

7. Technical support

Technical support for the product is provided via the Keenetic support portal, through which users may obtain product information and request assistance from the technical support team. The support portal is intended to assist with the installation, commissioning, configuration, software maintenance, troubleshooting and ongoing operation of the product throughout its supported lifetime.

KN-3411 (Buddy 6 Keenetic) is supported under a defined lifecycle support policy: Standard Updates until at least April 2029 , Limited Updates until at least April 2030 , and End of Support in April 2031. During the Standard Updates period, the product receives regular software updates, including security enhancements, new features, operating system updates, and bug fixes.

8. Security information

Security information for the product is provided through the product User Manual and related support resources. This information is intended to support the secure installation, configuration, administration, maintenance and use of the product throughout its supported lifecycle.

The security information includes guidance on initial secure setup, administrator password creation and account management, software updates, secure administration and remote access settings, wireless security settings, network protection features, guest network separation, and security-relevant diagnostic and recovery functions.

9. Foreseeable misuse and cybersecurity risks

Foreseeable circumstances and misuse scenarios that may lead to cybersecurity risks include:

  • Weak or reused administrator credentials, which may allow unauthorised access

  • Enabling remote management interfaces without adequate access restrictions or encryption

  • Disabling or bypassing network protection mechanisms

  • Use of outdated firmware without applying available security updates

  • Exposure of internal services to external networks through misconfiguration

  • Connection of untrusted or compromised devices to the local network

  • Use of insecure wireless configurations (e.g. weak passwords or legacy protocols)

  • Incorrect configuration of guest wireless networks or network segmentation

Such conditions may lead to risks including unauthorised access, data interception, service disruption, or misuse of network resources.