Impact
The Kaon AR2140X router generates a session cookie in the HTTP response to any unauthenticated request. A remote attacker can capture this cookie and then use it to invoke privileged firmware‑upgrade functions without providing credentials, bypassing authentication through an improper session cookie mechanism (CWE‑287). With a valid session token the attacker can execute unauthorized actions, including forcing the router to issue GET requests to arbitrary domains, which could be used for data exfiltration or delivery of malicious payloads.
Affected Systems
Kaon AR2140 routers running firmware versions up to 4.2.17 are affected. The status of firmware newer than 4.2.17 is currently unknown, so any device with firmware 4.2.17 or older must be assumed vulnerable until a confirmed patch is released or a safer configuration is applied.
Risk and Exploitability
The CVSS score of 5.3 classifies this as medium severity. An attacker only needs to send unauthenticated HTTP traffic to the router’s management port, making the exploit readily achievable from any network location with access to that port. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, so large‑scale exploitation has not yet been observed, but the ability to hijack firmware‑upgrade functionalities presents a clear vector for further compromise.
OpenCVE Enrichment