CVE-2026-52748
Missing authentication for backup functionality in Kaon AR2140X
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
| CWE | CWE-306 |
| Vendor | kaon |
| Product | ar2140 |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for kaon ar2140
Be the first to know when new unknown vulnerabilities affecting kaon ar2140 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Kaon / AR2140
0 ≤ 4.2.17
Credits
Sebastian Jeż