AR2140 vulnerabilities
CVEs whose affected-version data names the AR2140 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-52748High· 7.1The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by…
▾ TwilightKaon · AR2140via NVD
CVE-2026-52749Medium· 5.3The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an auth…
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an auth…
▾ SunlitKaon · AR2140via NVD