Impact
Firmware in KAON PG5298A and PG5298B routers allows an authenticated user to send crafted JSON‑RPC requests that trigger operations not exposed by the graphical user interface, including system file reads and arbitrary command execution. This vulnerability enables the attacker to read sensitive files, modify configuration, or run commands with the privileges of the authenticated account, thereby compromising the confidentiality, integrity, and availability of the device.
Affected Systems
Affected products are KAON PG5298A and KAON PG5298B routers. The fix is available in firmware version 3.0.82 for PG5298A and version 4.0.82 for PG5298B. Earlier firmware versions are vulnerable.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. No EPSS score is available, so current exploitation likelihood is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is network‑based, requiring authentication to the router’s administrative interface to craft and send malicious JSON‑RPC payloads. Exposing the JSON‑RPC interface to untrusted networks or allowing weak credentials would increase the risk significantly.
OpenCVE Enrichment