Cyber News / Article / Vulnerabilities in KAON PG5298A/PG5298B routers

Vulnerabilities in KAON PG5298A/PG5298B routers
CERT Polska has received a report about vulnerabilities in KAON PG5298A/PG5298B routers and participated in coordination of their disclosure.
The vulnerabilityCVE-2025-63080: Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
The vulnerabilityCVE-2026-6017: Firmware in KAON PG5298A and PG5298B routers allows an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.
These vulnerabilities have been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
We thank Oskar RudziÅski for reporting CVE-2025-63080 and MikoÅaj Pisula for reporting CVE-2026-6017.
Related articles
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
5 days ago
MikroTik Patches Critical Flaws Chained to Hack Routers
3 days ago
Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days
3 days ago
