Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-52748 2 Kaon, Kaongroup 2 Ar2140, Ar2140 2026-09-28 N/A
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.  This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
CVE-2026-52749 1 Kaon 1 Ar2140 2026-09-28 N/A
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
CVE-2026-6017 1 Kaon 2 Pg5298a, Pg5298b 2026-08-24 N/A
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.   This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
CVE-2025-63080 1 Kaon 2 Pg5298a, Pg5298b 2026-08-24 N/A
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.    This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.