CVE ID | CVE-2024-3659 |
Publication date | 08 August 2024 |
Vendor | KAON Group |
Product | AR2140 |
Vulnerable versions | From 3.2.46 before 4.2.16 |
Vulnerability type (CWE) | Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77) |
Report source | Report to CERT Polska |
Description
CERT Polska received a report about vulnerability in KAON Group AR2140 routers firmware and participated in coordination of its disclosure.
The vulnerability CVE-2024-3659 in KAON Group AR2140 routers allows for a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
The oldest tested firmware version is 3.2.46 and older ones might be vulnerable as well. The patch fixing this vulnerability was released in version 4.2.16.
Credits
We thank Arkadiusz Maruszczak for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.