Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints.
In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 03 Oct 2025 09:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics | cvssV4_0 
 | 
Mon, 12 Aug 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Kaongroup Kaongroup ar2140 Kaongroup ar2140 Firmware | |
| CPEs | cpe:2.3:h:kaongroup:ar2140:-:*:*:*:*:*:*:* cpe:2.3:o:kaongroup:ar2140_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Kaongroup Kaongroup ar2140 Kaongroup ar2140 Firmware | 
Thu, 08 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Kaonmedia Kaonmedia ar2140 Firmware | |
| CPEs | cpe:2.3:o:kaonmedia:ar2140_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Kaonmedia Kaonmedia ar2140 Firmware | |
| Metrics | cvssV3_1 
 
 | 
Thu, 08 Aug 2024 12:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router. | |
| Title | Command injection in KAON AR2140 routers | |
| Weaknesses | CWE-77 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: CERT-PL
Published: 2024-08-08T12:24:46.674Z
Updated: 2025-10-03T09:02:30.347Z
Reserved: 2024-04-11T15:53:39.381Z
Link: CVE-2024-3659
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-08T14:08:30.800Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-08-08T13:15:13.823
Modified: 2025-10-03T09:15:34.100
Link: CVE-2024-3659
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow