Command injection in KAON AR2140 routers
Description
Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
KAON AR2140 router firmware (3.2.46–<4.2.16) allows authenticated admin shell command injection via crafted request to an endpoint.
Vulnerability
CVE-2024-3659 is a shell command injection vulnerability in the firmware of KAON AR2140 routers, classified as CWE-77 (Improper Neutralization of Special Elements used in a Command). The flaw resides in one of the router's endpoints and is present in firmware versions from 3.2.46 up to, but not including, 4.2.16. Older versions (below 3.2.46) were not tested but may also be affected [1], [2].
Exploitation
An attacker must already have access to the administrative portal of the router. With that access, they can send a crafted request to the vulnerable endpoint, which does not properly sanitize special shell characters, allowing injection of arbitrary operating system commands [1], [2].
Impact
Successful exploitation enables the attacker to execute arbitrary shell commands on the router's underlying operating system. This gives the attacker high-privileged control over the device, potentially allowing full compromise of network traffic, device configuration, and connected systems [1], [2].
Mitigation
KAON released firmware version 4.2.16 which fixes the vulnerability. Users are advised to update to this version or later. For routers still running versions prior to 4.2.16, the only workaround is to restrict access to the administrative portal to trusted users only, as network-level filtering cannot fully mitigate the issue. No other public advisory or KEV listing is available [1], [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- KAON Group/AR2140v5Range: 3.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert.pl/en/posts/2024/08/CVE-2024-3659mitrethird-party-advisory
- cert.pl/posts/2024/08/CVE-2024-3659mitrethird-party-advisory
News mentions
0No linked articles in our index yet.