CVE-2024-3659: Kaongroup AR2140 Firmware
High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.
Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
Affected products
- Kaongroup AR2140 Firmware: from 3.2.46, before 4.2.16 (fixed in 4.2.16)
Published 2024-08-08. Last modified 2026-06-17.