Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
History

Mon, 12 Aug 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Kaongroup
Kaongroup ar2140
Kaongroup ar2140 Firmware
CPEs cpe:2.3:h:kaongroup:ar2140:-:*:*:*:*:*:*:*
cpe:2.3:o:kaongroup:ar2140_firmware:*:*:*:*:*:*:*:*
Vendors & Products Kaongroup
Kaongroup ar2140
Kaongroup ar2140 Firmware

Thu, 08 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Kaonmedia
Kaonmedia ar2140 Firmware
CPEs cpe:2.3:o:kaonmedia:ar2140_firmware:*:*:*:*:*:*:*:*
Vendors & Products Kaonmedia
Kaonmedia ar2140 Firmware
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 12:45:00 +0000

Type Values Removed Values Added
Description Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
Title Command injection in KAON AR2140 routers
Weaknesses CWE-77
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2024-08-08T12:24:46.674Z

Updated: 2024-08-08T14:14:37.496Z

Reserved: 2024-04-11T15:53:39.381Z

Link: CVE-2024-3659

cve-icon Vulnrichment

Updated: 2024-08-08T14:08:30.800Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T13:15:13.823

Modified: 2024-08-12T15:57:06.257

Link: CVE-2024-3659

cve-icon Redhat

No data.