GHSA-vcfv-29fp-vc3cHigh
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible...
🔗 CVE IDs covered (1)
📋 Description
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.