CVE-2026-52748EPSS p15.5%
CVE-2026-52748CVE-2026-52748
Description
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Scoring
| EPSS | 0.25% probability of exploitation · percentile 15.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |