VYPR

AR2140X router

by KAON

CVEs (2)

  • CVE-2026-52748HigSep 28, 2026
    risk 0.46cvss —epss —

    The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this…

  • CVE-2026-52749MedSep 28, 2026
    risk 0.34cvss —epss —

    The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the…