Description
Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.   
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
Published: 2026-08-24
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON‑RPC requests that trigger operations not exposed by the graphical user interface, including system file reads and arbitrary command execution. This vulnerability enables the attacker to read sensitive files, modify configuration, or run commands with the privileges of the authenticated account, thereby compromising the confidentiality, integrity, and availability of the device.

Affected Systems

Affected products are KAON PG5298A and KAON PG5298B routers. The fix is available in firmware version 3.0.82 for PG5298A and version 4.0.82 for PG5298B. Earlier firmware versions are vulnerable.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. No EPSS score is available, so current exploitation likelihood is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is network‑based, requiring authentication to the router’s administrative interface to craft and send malicious JSON‑RPC payloads. Exposing the JSON‑RPC interface to untrusted networks or allowing weak credentials would increase the risk significantly.

Generated by OpenCVE AI on August 24, 2026 at 12:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply firmware update 3.0.82 for PG5298A or 4.0.82 for PG5298B to fix the vulnerability
  • Restrict network exposure of the JSON‑RPC interface and enforce strong authentication to limit access only to trusted administrators
  • Monitor router logs for anomalous JSON‑RPC requests and unauthorized file access attempts

Generated by OpenCVE AI on August 24, 2026 at 12:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.    This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.
Title Authenticated RCE in KAON PG5298
First Time appeared Kaon
Kaon pg5298a
Kaon pg5298b
Weaknesses CWE-863
CPEs cpe:2.3:a:kaon:pg5298a:*:*:*:*:*:*:*:*
cpe:2.3:a:kaon:pg5298b:*:*:*:*:*:*:*:*
Vendors & Products Kaon
Kaon pg5298a
Kaon pg5298b
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-08-24T11:11:24.083Z

Reserved: 2025-10-24T15:51:09.965Z

Link: CVE-2025-63080

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T12:16:47.937

Modified: 2026-08-24T12:16:47.937

Link: CVE-2025-63080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T12:30:16Z

Weaknesses