CVE-2025-63080
8.5KAON · PG5298A and PG5298B
Firmware in KAON PG5298A and PG5298B routers allows authenticated users to execute unauthorized operations via crafted JSON-RPC requests.
Executive summary
An incorrect authorization vulnerability in KAON PG5298A and PG5298B routers allows authenticated users to perform unauthorized administrative operations, posing a significant risk to device integrity.
Vulnerability
The vulnerability involves incorrect authorization (CWE-863) within the device firmware. An attacker with authenticated access can send crafted JSON-RPC requests to trigger functions that are intended to be restricted, bypassing GUI-based limitations.
Business impact
Successful exploitation allows an authenticated attacker to perform operations outside their authorized scope, potentially leading to full device compromise or configuration changes. With a CVSS score of 8.5, this high-severity flaw represents a substantial threat to network infrastructure and data confidentiality if the routers manage sensitive traffic.
Remediation
Immediate Action: Update the firmware on affected KAON PG5298A devices to version 3.0.82 or later, and KAON PG5298B devices to version 4.0.82 or later.
Proactive Monitoring: Review device access logs for suspicious or malformed JSON-RPC requests and monitor for unexpected changes in router configurations.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only, and ensure that only authorized personnel have credentials for the device.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for unauthorized administrative control, administrators should prioritize firmware updates for all deployed KAON PG5298A and PG5298B units. Failure to patch these devices leaves the network vulnerable to internal configuration tampering and potential service disruption.