Newsy / CERT
Vulnerabilities in KAON PG5298A/PG5298B routers
CVE ID: CVE-2025-63080
Publication date: 24 August 2026
Vendor: KAON
Product: PG5298APG5298B
Vulnerable versions: PG5298A: All before 3.0.82PG5298B: All before 4.0.82
Vulnerability type (CWE): Incorrect Authorization (CWE-863)
Report source: Report to CERT Polska
CVE ID: CVE-2026-6017
Publication date: 24 August 2026
Vendor: KAON
Product: PG5298APG5298B
Vulnerable versions: PG5298A: All before 3.0.82PG5298B: All before 4.0.82
Vulnerability type (CWE): Missing Authentication for Critical Function (CWE-306)
Report source: Report to CERT Polska
Description
CERT Polska has received a report about vulnerabilities in KAON PG5298A/PG5298B routers and participated in coordination of their disclosure.
The vulnerability CVE-2025-63080: Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
The vulnerability CVE-2026-6017: Firmware in KAON PG5298A and PG5298B routers allows an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.
These vulnerabilities have been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
Credits
We thank Oskar Rudziński for reporting CVE-2025-63080 and Mikołaj Pisula for reporting CVE-2026-6017.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.