Firmware in KAONÂ AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints.
In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2024/08/CVE-2024-3659 | Third Party Advisory |
https://cert.pl/posts/2024/08/CVE-2024-3659 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-08-08 13:15
Updated : 2024-08-12 15:57
NVD link : CVE-2024-3659
Mitre link : CVE-2024-3659
CVE.ORG link : CVE-2024-3659
JSON object : View
Products Affected
kaongroup
- ar2140
- ar2140_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')