---
id: CVE-2026-52748
title: >-
  The Kaon AR2140X router contains a vulnerability where the backup
  functionality is accessible without authentication
summary: >-
  The Kaon AR2140X router contains a vulnerability where the backup
  functionality is accessible without authentication. This allows an
  unauthenticated remote attacker to trigger a configuration backup and retrieve
  it in a form encrypted by…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: Kaon
product: AR2140
affected:
  - AR2140 <= 4.2.17
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T13:17:21.847'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52748'
references:
  - url: 'https://cert.pl/en/posts/2026/09/CVE-2026-52748'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-28T13:19:21.836649Z'
cvssSource: cna
ingestedAt: '2026-09-28T13:09:42.229Z'
---

## Overview

The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time. 



This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
