Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-52748— Missing authentication for backup functionality in Kaon AR2140X

Quick assessment

Affected
Kaon AR2140
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kaon AR2140X 路由器存在一个安全漏洞,其备份功能可在未进行身份验证的情况下访问。这使得未认证的远程攻击者能够触发配置备份,并以设备特定密钥加密的形式获取该备份文件。触发此功能会导致路由器在较长时间内无法正常工作。 该问题已在固件版本 4.2.17 及更早版本中被发现,较新固件版本的状态尚不明确。

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-52748

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing authentication for backup functionality in Kaon AR2140X
Source: CVE Program / CVE List V5
Vulnerability Description
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.  This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kaon AR2140 0 ~ 4.2.17 -

II. Public POCs for CVE-2026-52748

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-52748

请登录查看更多情报信息。

Other References for CVE-2026-52748 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-52748

No comments yet


Leave a comment