rootpwn

high · CVSS v3 7.5 · CVSS v4 7.1

CVE-2026-52748

The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. Th…

Description

The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
7.1
EPSS
—

← All CVEs