Impact
The vulnerability in KAON PG5298A and PG5298B routers is a missing authentication flaw that permits an unauthenticated user to access a privileged endpoint. By querying this endpoint, an attacker can retrieve sensitive data such as the administrator account password. This flaw is classified as CWE‑306, indicating an absence of proper authentication controls.
Affected Systems
Affected devices are KAON PG5298A and PG5298B routers running firmware versions earlier than 3.0.82 and 4.0.82, respectively. The vendor has released updated firmware versions that rectify the issue, so updating the device to these versions removes the vulnerability. No other versions or variants were explicitly listed in the advisory.
Risk and Exploitability
The assessed CVSS score of 7.1 indicates a high severity level, although the EPSS score is not available, making the exact exploitation probability unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The likely attack vector is remote, as the flaw can be triggered by an external user sending a request to the router's HTTP endpoint without authentication.
OpenCVE Enrichment