CERT Polska disclosed two vulnerabilities in KAON PG5298A and PG5298B routers that could expose sensitive data and enable unauthorized actions. The flaws, tracked as CVE-2025-63080 and CVE-2026-6017, affect all PG5298A firmware versions before 3.0.82 and all PG5298B firmware versions before 4.0.82. CVE-2026-6017 is a missing authentication issue that lets an unauthenticated attacker query a specific endpoint and retrieve sensitive information, including the administrative portal password.
CERT Polska said CVE-2025-63080 is an incorrect authorization flaw that allows an authenticated user to send crafted JSON-RPC requests to perform actions not exposed in the web interface, including reading system files or executing commands. KAON has released fixes in firmware 3.0.82 for PG5298A and 4.0.82 for PG5298B, and the disclosure credits researcher Oskar Rudziński for responsibly reporting the issues.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CERT Polska disclosed CVE-2025-63080 and CVE-2026-6017 affecting KAON PG5298A and PG5298B routers, and noted it coordinated the disclosure after receiving a responsible report from Oskar Rudziński. The disclosure described one incorrect authorization flaw enabling file read or command execution for authenticated users and one missing authentication flaw exposing sensitive information, including the admin portal password, to unauthenticated users.
KAON fixed CVE-2025-63080 and CVE-2026-6017 in firmware version 3.0.82 for PG5298A and 4.0.82 for PG5298B. The flaws affect earlier firmware versions on both router models.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecert.pl
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.