SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-63080

HIGH · CVSS 8.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The firmware in KAON PG5298A and PG5298B routers is vulnerable, allowing authenticated users to exploit crafted JSON-RPC requests to perform unauthorized operations, such as reading system files or executing commands. This high-severity vulnerability poses significant risks to network security and should be prioritized by organizations using these router models to ensure they update to firmware versions 3.0.82 and 4.0.82, respectively.

CVE
CVE-2025-63080
Severity
HIGH
CVSS
8.5
EPSS
0.34%

Original NVD Description

Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.    This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.