Unauthorized Information Disclosure in KAON Routers PG5298A and PG5298B
CVE-2026-6017

7.1HIGH

Key Information:

Vendor

Kaon

Vendor
CVE Published:
24 August 2026

What is CVE-2026-6017?

Firmware in KAON PG5298A and PG5298B routers allows an unauthenticated user to access sensitive information by querying a specific endpoint, potentially exposing passwords to the administrative portal. This security risk underscores the importance of maintaining updated firmware, as versions 3.0.82 for PG5298A and 4.0.82 for PG5298B address this vulnerability.

Affected Version(s)

PG5298A 0 < 3.0.82

PG5298B 0 < 4.0.82

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mikołaj Pisula
.