CVE-2025-63080

8.5

KAON · PG5298A and PG5298B

Firmware in KAON PG5298A and PG5298B routers allows authenticated users to execute unauthorized operations via crafted JSON-RPC requests.

Executive summary

An incorrect authorization vulnerability in KAON PG5298A and PG5298B routers allows authenticated users to perform unauthorized administrative operations, posing a significant risk to device integrity.

Vulnerability

The vulnerability involves incorrect authorization (CWE-863) within the device firmware. An attacker with authenticated access can send crafted JSON-RPC requests to trigger functions that are intended to be restricted, bypassing GUI-based limitations.

Business impact

Successful exploitation allows an authenticated attacker to perform operations outside their authorized scope, potentially leading to full device compromise or configuration changes. With a CVSS score of 8.5, this high-severity flaw represents a substantial threat to network infrastructure and data confidentiality if the routers manage sensitive traffic.

Remediation

Immediate Action: Update the firmware on affected KAON PG5298A devices to version 3.0.82 or later, and KAON PG5298B devices to version 4.0.82 or later.

Proactive Monitoring: Review device access logs for suspicious or malformed JSON-RPC requests and monitor for unexpected changes in router configurations.

Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only, and ensure that only authorized personnel have credentials for the device.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for unauthorized administrative control, administrators should prioritize firmware updates for all deployed KAON PG5298A and PG5298B units. Failure to patch these devices leaves the network vulnerable to internal configuration tampering and potential service disruption.