Authentication Bypass in Kaon AR2140X Router
CVE-2026-52749

5.3MEDIUM

Key Information:

Vendor

Kaon

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-52749?

The Kaon AR2140X router is vulnerable due to improper handling of session cookies in responses to unauthenticated HTTP requests. This flaw enables remote attackers to obtain valid session identifiers without needing credentials, leading to unauthorized actions on the device, particularly concerning upgrade functionalities. Consequently, the attacker can manipulate the router to send GET requests to any specified domain, posing significant security risks.

Affected Version(s)

AR2140 0 <= 4.2.17

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sebastian Jeż
.