CVE-2026-52748: Missing authentication for backup functionality in Kaon AR2140X
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Affected Software
Event History
Frequently Asked Questions
Which devices should be considered affected?
Kaon AR2140X routers running firmware versions up to 4.2.17 are affected. The status of versions newer than 4.2.17 is unknown.
What does an attacker need to exploit this issue?
An attacker needs remote network access to the router's backup functionality; no authentication is required. They can trigger a configuration backup and retrieve the resulting device-key-encrypted backup.
What operational impact can exploitation have?
Triggering the backup function renders the router inoperable for a substantial period of time. This can create a denial-of-service condition even if the attacker cannot decrypt the retrieved backup.