CVE-2024-3659
Severity CVSS v4.0:
CRITICAL
Type:
CWE-78
OS Command Injections
Publication date:
08/08/2024
Last modified:
17/11/2025
Description
Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints.<br />
In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:kaongroup:ar2140_firmware:*:*:*:*:*:*:*:* | 3.2.46 (including) | 4.2.16 (excluding) |
| cpe:2.3:h:kaongroup:ar2140:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



