This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2026/09/CVE-2026-52748 |
|
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown. | |
| Title | Improper Authentication in Kaon AR2140X | |
| First Time appeared |
Kaon
Kaon ar2140 |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:kaon:ar2140:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kaon
Kaon ar2140 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-28T13:31:27.330Z
Reserved: 2026-06-08T14:40:31.450Z
Link: CVE-2026-52749
Updated: 2026-09-28T13:23:56.576Z
Status : Received
Published: 2026-09-28T13:17:22.007
Modified: 2026-09-28T14:17:16.000
Link: CVE-2026-52749
No data.
OpenCVE Enrichment
No data.