| CVE ID | CVE-2026-52748 |
| Publication date | 28 September 2026 |
| Vendor | Kaon |
| Product | AR2140 |
| Vulnerable versions | All through 4.2.17 |
| Vulnerability type (CWE) | Missing authentication for critical function (CWE-306) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-52749 |
| Publication date | 28 September 2026 |
| Vendor | Kaon |
| Product | AR2140 |
| Vulnerable versions | All through 4.2.17 |
| Vulnerability type (CWE) | Improper Authentication (CWE-287) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in firmware of Kaon AR2140 routers and participated in coordination of their disclosure.
The vulnerability CVE-2026-52748: The Kaon AR2140 router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
The vulnerability CVE-2026-52749: The Kaon AR2140 router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.
These issues were identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Credits
We thank Sebastian Jeż for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.