CVE-2025-63080
Authenticated RCE in KAON PG5298
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution. This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
| CWE | CWE-863 |
| Vendor | kaon |
| Product | pg5298a |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for kaon pg5298a
Be the first to know when new unknown vulnerabilities affecting kaon pg5298a are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
KAON / PG5298A
0 < 3.0.82
KAON / PG5298B
0 < 4.0.82
Credits
Oskar Rudziński