CVE-2024-3659

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kaongroup:ar2140_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:kaongroup:ar2140:-:*:*:*:*:*:*:*

History

17 Nov 2025, 17:15

Type Values Removed Values Added
Summary (en) Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router. (en) Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.

Information

Published : 2024-08-08 13:15

Updated : 2025-11-17 17:15


NVD link : CVE-2024-3659

Mitre link : CVE-2024-3659

CVE.ORG link : CVE-2024-3659


JSON object : View

Products Affected

kaongroup

  • ar2140_firmware
  • ar2140
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')