CVE-2026-6017
Received Received - Intake

Information Disclosure in KAON PG5298A and PG5298B Routers

Vulnerability report for CVE-2026-6017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: CERT.PL

Description

Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal. Β  This vulnerability has been fixed in firmware version: 3.0.82Β for PG5298A and 4.0.82 for PG5298B.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
kaon pg5298a 3.0.82
kaon pg5298b 4.0.82
kaon pg5298a to 3.0.82 (exc)
kaon pg5298b to 4.0.82 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated user to query a specific endpoint in KAON PG5298A and PG5298B routers to retrieve sensitive information, including the administrative portal password.

Detection Guidance

Check router firmware versions for PG5298A (must be 3.0.82 or higher) and PG5298B (must be 4.0.82 or higher). Test by querying the vulnerable endpoint to see if sensitive information is exposed.

Impact Analysis

An attacker could gain access to the router's administrative portal, allowing them to modify settings, intercept network traffic, or launch further attacks on connected devices.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements if the router handles such data.

Mitigation Strategies

Update firmware to version 3.0.82 for PG5298A or 4.0.82 for PG5298B. Restrict network access to the router's administrative interface to prevent unauthenticated queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart