CVE-2026-6017: Missing Authentication for Critical Function in KAON PG5298
Published Aug 24, 2026
·Updated
Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
Affected Software
2 affected components
KAON KAON PG5298A router firmware
KAON KAON PG5298B router firmware
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
KAON PG5298A firmwareto a version that resolves this vulnerability.Fixed in 3.0.82 - Upgrade
Upgrade
KAON PG5298B firmwareto a version that resolves this vulnerability.Fixed in 4.0.82
Event History
Aug 24, 2026
CVE Published
via MITRE·11:11 AM
Data Sourced
via MITRE·11:11 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which firmware versions contain the fix?
The issue is fixed in firmware version 3.0.82 for the PG5298A and 4.0.82 for the PG5298B.
2
What could an unauthenticated attacker obtain?
An unauthenticated user can query a specific endpoint and obtain sensitive information, including a password for the administrative portal.