Impact
The vulnerability allows an unauthenticated attacker to invoke the router’s backup function, producing an encrypted configuration file that can be retrieved by the attacker. Once the backup has been triggered, the device is rendered inoperable for a substantial period. Because no authentication is required, any remote host that can reach the router’s backup endpoint can exploit the flaw. The weakness is a classic Missing Authentication (CWE-306) that permits data exfiltration and denial of service.
Affected Systems
Kaon AR2140X routers running firmware versions up to 4.2.17 are impacted. Newer firmware releases have not been verified as patched, so all devices on the network that remain on or below 4.2.17 are at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity. The EPSS score is currently not available, so the recentness of exploitation is uncertain, but the lack of authentication makes exploitation straightforward for any remote attacker who can reach the router. The vulnerability is not listed in the CISA KEV catalog, yet it remains a potential target for network reconnaissance and automated backup requests. An attacker who can dial in to the backup endpoint can cause a denial of service by forcing the router to crash. The risk therefore remains significant until a mitigated firmware or workaround is deployed.
OpenCVE Enrichment