This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2026/09/CVE-2026-52748 |
|
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown. | |
| Title | Improper Authentication in Kaon AR2140X | |
| First Time appeared |
Kaon
Kaon ar2140 |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:kaon:ar2140:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kaon
Kaon ar2140 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-28T13:31:27.330Z
Reserved: 2026-06-08T14:40:31.450Z
Link: CVE-2026-52749
Updated: 2026-09-28T13:23:56.576Z
Status : Received
Published: 2026-09-28T13:17:22.007
Modified: 2026-09-28T14:17:16.000
Link: CVE-2026-52749
No data.
OpenCVE Enrichment
No data.