Executive brief
KAON PG5298A and PG5298B are commonly deployed residential gateway routers used to provide internet connectivity and network management. A vulnerability in the router firmware allows authenticated users to bypass the graphical interface and execute unauthorized operations, including reading system files or executing arbitrary commands on the device. This could enable an attacker with basic user credentials to gain full control of the router and compromise the entire network it protects.
Technical details
CVE-2025-63080 is an incorrect authorization vulnerability (CWE-863) in the JSON-RPC interface of KAON PG5298A and PG5298B routers. An authenticated attacker can craft JSON-RPC requests that bypass the GUI-level access controls, allowing direct execution of privileged operations not normally exposed through the web interface, such as arbitrary file reads or command execution. The attack requires valid authentication credentials but no additional user interaction. The vulnerability affects all firmware versions prior to 3.0.82 (PG5298A) and 4.0.82 (PG5298B), and patches have been released by the vendor.
Affected products
- KAON PG5298A before 3.0.82
- KAON PG5298B before 4.0.82
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Firmware 3.0.82 for PG5298A and 4.0.82 for PG5298B