| CVE ID | CVE-2025-63080 |
| Publication date | 24 August 2026 |
| Vendor | KAON |
| Product | PG5298A PG5298B |
| Vulnerable versions | PG5298A: All before 3.0.82 PG5298B: All before 4.0.82 |
| Vulnerability type (CWE) | Incorrect Authorization (CWE-863) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-6017 |
| Publication date | 24 August 2026 |
| Vendor | KAON |
| Product | PG5298A PG5298B |
| Vulnerable versions | PG5298A: All before 3.0.82 PG5298B: All before 4.0.82 |
| Vulnerability type (CWE) | Missing Authentication for Critical Function (CWE-306) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in KAON PG5298A/PG5298B routers and participated in coordination of their disclosure.
The vulnerability CVE-2025-63080: Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
The vulnerability CVE-2026-6017: Firmware in KAON PG5298A and PG5298B routers allows an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.
These vulnerabilities have been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
Credits
We thank Oskar Rudziński for reporting CVE-2025-63080 and Mikołaj Pisula for reporting CVE-2026-6017.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.