CERT Polska disclosed two vulnerabilities in Kaon AR2140 router firmware through version 4.2.17: CVE-2026-52748 and CVE-2026-52749. The first exposes backup functionality without authentication, enabling a remote attacker to retrieve a configuration backup encrypted with a device-specific key; requests can also leave the device inoperable for a substantial period.
CVE-2026-52749 causes unauthenticated HTTP responses to issue session cookies, allowing a remote attacker to obtain a valid session identifier and bypass authentication. An attacker can then access upgrade-related functions, including inducing the router to send GET requests to attacker-controlled domains. The security status of firmware releases newer than 4.2.17 remains unknown.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
CERT Polska published CVE-2026-52748 and CVE-2026-52749, responsibly reported by Sebastian Jeż, affecting Kaon AR2140 firmware through version 4.2.17. CVE-2026-52748 exposes backup functionality without authentication and can leave a device inoperable, while CVE-2026-52749 can issue a valid session cookie to unauthenticated users, enabling authentication bypass and unauthorized upgrade-related actions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.