CVE-2024-3659: Kaongroup AR2140 Firmware

High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.

Affected products

  • Kaongroup AR2140 Firmware: from 3.2.46, before 4.2.16 (fixed in 4.2.16)

Published 2024-08-08. Last modified 2026-06-17.