ALPHACON BBSGość · pl
← Newsy

Newsy / CERT

Vulnerabilities in KAON PG5298A/PG5298B routers

CVE ID: CVE-2025-63080

Publication date: 24 August 2026

Vendor: KAON

Product: PG5298APG5298B

Vulnerable versions: PG5298A: All before 3.0.82PG5298B: All before 4.0.82

Vulnerability type (CWE): Incorrect Authorization (CWE-863)

Report source: Report to CERT Polska

CVE ID: CVE-2026-6017

Publication date: 24 August 2026

Vendor: KAON

Product: PG5298APG5298B

Vulnerable versions: PG5298A: All before 3.0.82PG5298B: All before 4.0.82

Vulnerability type (CWE): Missing Authentication for Critical Function (CWE-306)

Report source: Report to CERT Polska

Description

CERT Polska has received a report about vulnerabilities in KAON PG5298A/PG5298B routers and participated in coordination of their disclosure.

The vulnerability CVE-2025-63080: Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.

The vulnerability CVE-2026-6017: Firmware in KAON PG5298A and PG5298B routers allows an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.

These vulnerabilities have been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

Credits

We thank Oskar Rudziński for reporting CVE-2025-63080 and Mikołaj Pisula for reporting CVE-2026-6017.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.