Full Report
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-52748 and CVE-2026-52749) found in Kaon AR2140 routers.
Analysis Summary
# Vulnerability: Authentication Bypass and Denial of Service in Kaon AR2140 Routers
## CVE Details
- **CVE ID**: CVE-2026-52748
- **CVSS Score**: Not explicitly provided in the source (Typically High/Critical for unauthenticated RCE/DoS)
- **CWE**: CWE-306 (Missing Authentication for Critical Function)
- **CVE ID**: CVE-2026-52749
- **CVSS Score**: Not explicitly provided in the source (Typically High for Authentication Bypass)
- **CWE**: CWE-287 (Improper Authentication)
## Affected Systems
- **Products**: Kaon AR2140 Routers
- **Versions**: All versions through 4.2.17
- **Configurations**: Devices with web management interfaces accessible to the attacker.
## Vulnerability Description
The Kaon AR2140 router suffers from two distinct authentication-related flaws:
1. **CVE-2026-52748**: The device fails to require authentication for its configuration backup functionality. An attacker can remotely trigger a backup process. While the resulting file is encrypted with a device-specific key, the process of generating the backup causes the router to become unresponsive and inoperable for a significant duration.
2. **CVE-2026-52749**: The router's web server improperly issues valid session cookies in response to unauthenticated HTTP requests. By obtaining a session identifier without providing credentials, an attacker can bypass authentication to access upgrade-related features. This can be further leveraged to force the router to make outbound GET requests to arbitrary external domains (SSRF-like behavior).
## Exploitation
- **Status**: Reported to CERT Polska; no evidence of exploitation in the wild mentioned in the report.
- **Complexity**: Low
- **Attack Vector**: Network (Remote)
## Impact
- **Confidentiality**: Medium (Access to encrypted configuration files and session identifiers).
- **Integrity**: High (Ability to perform unauthorized actions on upgrade functionalities).
- **Availability**: High (Triggering backups leads to prolonged device inoperability/Denial of Service).
## Remediation
### Patches
- As of the publication date (September 28, 2026), firmware versions up to **4.2.17** are confirmed vulnerable. Users should contact Kaon or their Internet Service Provider (ISP) to check for firmware versions newer than 4.2.17.
### Workarounds
- **Restrict Access**: Ensure the router’s administration interface is not accessible from the Wide Area Network (WAN/Internet).
- **Network Segmentation**: Limit access to the router management interface to trusted local IP addresses only.
## Detection
- **Indicators of Compromise**: Monitor for unexpected outbound HTTP GET requests from the router to unknown external domains.
- **Detection Methods**: Audit logs for unauthorized access to the `/backup` or upgrade-related endpoints. Monitor for unexplained periods of device unresponsiveness which may indicate the backup process is being triggered maliciously.
## References
- CERT Polska Advisory: hxxps[://]cert[.]pl/en/posts/2026/09/vulnerabilities-in-kaon-ar2140-routers/
- CVE-2026-52748: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-52748
- CVE-2026-52749: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-52749
- CERT Polska CVD Policy: hxxps[://]cert[.]pl/en/cvd/