VORANT. Threat Intelligence Research Sign in Create a free account

CERT Polska discloses Kaon AR2140 router flaws

routine vulnerability telecommunications

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Two vulnerabilities in Kaon AR2140 router firmware allow unauthenticated attackers to cause denial of service and bypass authentication.

CERT Polska coordinated disclosure of two vulnerabilities affecting Kaon AR2140 routers running firmware up to version 4.2.17, reported by researcher Sebastian Jeż. The first, CVE-2026-52748, involves an unauthenticated backup function that can be triggered remotely to retrieve an encrypted configuration backup, but doing so renders the device inoperable for an extended period, effectively a denial-of-service vector. The second, CVE-2026-52749, stems from improper session cookie issuance in responses to unauthenticated HTTP requests, allowing an attacker to obtain a valid session identifier without credentials and bypass authentication entirely. With this bypassed access, an attacker can abuse upgrade-related functionality to force the router to issue GET requests to arbitrary attacker-chosen domains, a form of server-side request forgery (SSRF) affecting network-connected devices.

No exploitation in the wild has been reported; this is a coordinated disclosure rather than an active campaign. The status of firmware versions newer than 4.2.17 is unknown, and no patch information is provided in the advisory. Defenders operating Kaon AR2140 routers should verify firmware version, restrict management interface exposure to trusted networks, monitor for unexpected backup-trigger requests or unusual outbound GET requests originating from router upgrade functions, and contact the vendor for patch guidance given the lack of confirmed fixed versions in this bulletin.

Mentioned in this report

Vulnerabilities CVE-2026-52748CVE-2026-52749

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-52748

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,155 reports from 152 sources, 2,672 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs