{"id":"CVE-2026-52748","published":"2026-09-28T13:17:21.847","lastModified":"2026-09-28T16:31:16.073","description":"The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time. \n\n\n\nThis issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://cert.pl/en/posts/2026/09/CVE-2026-52748","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}