Command injection in KAON AR2140 routers
Vulnerability Description
Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3659
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Arkadiusz Maruszczak
Affected Vendor
KAON Group
View all reports →