CVE-2026-52749: Improper Authentication in Kaon AR2140X
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker who can send unauthenticated HTTP requests to the router can obtain a valid session identifier. No credentials are required.
What functionality is exposed after authentication bypass?
The obtained session can be used to perform unauthorized actions on upgrade-related functionality. Those actions can be abused to make the router send GET requests to attacker-chosen domains.
Which firmware versions are known to be affected?
Firmware versions up to 4.2.17 are affected. The status of versions newer than 4.2.17 is unknown.