Description
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.

This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass via Improper Session Cookie
Action: Patch ASAP
AI Analysis

Impact

The Kaon AR2140X router generates a session cookie in the HTTP response to any unauthenticated request. A remote attacker can capture this cookie and then use it to invoke privileged firmware‑upgrade functions without providing credentials, bypassing authentication through an improper session cookie mechanism (CWE‑287). With a valid session token the attacker can execute unauthorized actions, including forcing the router to issue GET requests to arbitrary domains, which could be used for data exfiltration or delivery of malicious payloads.

Affected Systems

Kaon AR2140 routers running firmware versions up to 4.2.17 are affected. The status of firmware newer than 4.2.17 is currently unknown, so any device with firmware 4.2.17 or older must be assumed vulnerable until a confirmed patch is released or a safer configuration is applied.

Risk and Exploitability

The CVSS score of 5.3 classifies this as medium severity. An attacker only needs to send unauthenticated HTTP traffic to the router’s management port, making the exploit readily achievable from any network location with access to that port. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, so large‑scale exploitation has not yet been observed, but the ability to hijack firmware‑upgrade functionalities presents a clear vector for further compromise.

Generated by OpenCVE AI on September 28, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update that corrects the session cookie handling for the Kaon AR2140 routers.
  • If no update is available, block external access to the router’s management interface by configuring firewall rules or VLAN segmentation so that only trusted internal hosts can reach the HTTP port.
  • Disable remote firmware upgrade or force stronger authentication (e.g., password plus two‑factor) on the web management interface until the vulnerability is patched.
  • Monitor router logs for unexpected session cookie issuance or unauthorized GET requests to external domains as an early warning of exploitation.

Generated by OpenCVE AI on September 28, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Title Improper Authentication in Kaon AR2140X
First Time appeared Kaon
Kaon ar2140
Weaknesses CWE-287
CPEs cpe:2.3:a:kaon:ar2140:*:*:*:*:*:*:*:*
Vendors & Products Kaon
Kaon ar2140
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:27.330Z

Reserved: 2026-06-08T14:40:31.450Z

Link: CVE-2026-52749

cve-icon Vulnrichment

Updated: 2026-09-28T13:23:56.576Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:22.007

Modified: 2026-09-28T16:31:16.073

Link: CVE-2026-52749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:00:03Z

Weaknesses