# CERT Polska discloses Kaon AR2140 router flaws

Published: 2026-09-28 · Severity: routine · Sectors: telecommunications
Canonical: https://vorant.io/reports/408fd293-798c-5881-9e07-95fa68cd792d/cert-polska-discloses-kaon-ar2140-router-flaws

> Two vulnerabilities in Kaon AR2140 router firmware allow unauthenticated attackers to cause denial of service and bypass authentication.

CERT Polska coordinated disclosure of two vulnerabilities affecting Kaon AR2140 routers running firmware up to version 4.2.17, reported by researcher Sebastian Jeż. The first, CVE-2026-52748, involves an unauthenticated backup function that can be triggered remotely to retrieve an encrypted configuration backup, but doing so renders the device inoperable for an extended period, effectively a denial-of-service vector. The second, CVE-2026-52749, stems from improper session cookie issuance in responses to unauthenticated HTTP requests, allowing an attacker to obtain a valid session identifier without credentials and bypass authentication entirely. With this bypassed access, an attacker can abuse upgrade-related functionality to force the router to issue GET requests to arbitrary attacker-chosen domains, a form of server-side request forgery (SSRF) affecting network-connected devices.

No exploitation in the wild has been reported; this is a coordinated disclosure rather than an active campaign. The status of firmware versions newer than 4.2.17 is unknown, and no patch information is provided in the advisory. Defenders operating Kaon AR2140 routers should verify firmware version, restrict management interface exposure to trusted networks, monitor for unexpected backup-trigger requests or unusual outbound GET requests originating from router upgrade functions, and contact the vendor for patch guidance given the lack of confirmed fixed versions in this bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-52748, CVE-2026-52749

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-52748

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/408fd293-798c-5881-9e07-95fa68cd792d/cert-polska-discloses-kaon-ar2140-router-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
