{"id":"CVE-2026-52748","title":"The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication","summary":"The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by…","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-306"],"vendor":"Kaon","product":"AR2140","affected":["AR2140 <= 4.2.17"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T13:17:21.847","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52748","references":[{"url":"https://cert.pl/en/posts/2026/09/CVE-2026-52748","label":"cvd@cert.pl"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-28T13:19:21.836649Z"},"cvssSource":"cna","ingestedAt":"2026-09-28T13:09:42.229Z","slug":"CVE-2026-52748","body":"## Overview\n\nThe Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time. \n\n\n\nThis issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}