Article

    Cyber News / Article / Vulnerabilities in KAON PG5298A/PG5298B routers

    Vulnerabilities in KAON PG5298A/PG5298B routers
    CE
    CERT Polska-18 days ago

    Vulnerabilities in KAON PG5298A/PG5298B routers

    CERT Polska has received a report about vulnerabilities in KAON PG5298A/PG5298B routers and participated in coordination of their disclosure.

    The vulnerabilityCVE-2025-63080: Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.

    The vulnerabilityCVE-2026-6017: Firmware in KAON PG5298A and PG5298B routers allows an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.

    These vulnerabilities have been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

    We thank Oskar Rudziński for reporting CVE-2025-63080 and Mikołaj Pisula for reporting CVE-2026-6017.

    Original source