CVE-2024-3659

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kaongroup:ar2140_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:kaongroup:ar2140:-:*:*:*:*:*:*:*

History

17 Nov 2025, 17:15

Type Values Removed Values Added
Summary (en) Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router. (en) Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.

03 Oct 2025, 09:15

Type Values Removed Values Added
CWE CWE-78

12 Aug 2024, 15:57

Type Values Removed Values Added
CPE cpe:2.3:h:kaongroup:ar2140:-:*:*:*:*:*:*:*
cpe:2.3:o:kaongroup:ar2140_firmware:*:*:*:*:*:*:*:*
Summary
  • (es) El firmware de los enrutadores KAON AR2140 anteriores a la versión 4.2.16 es vulnerable a la inyección de un comando de shell mediante el envío de una solicitud manipulada a uno de los endpoints. Para aprovechar esta vulnerabilidad, es necesario tener acceso al portal administrativo del enrutador.
References () https://cert.pl/en/posts/2024/08/CVE-2024-3659 - () https://cert.pl/en/posts/2024/08/CVE-2024-3659 - Third Party Advisory
References () https://cert.pl/posts/2024/08/CVE-2024-3659 - () https://cert.pl/posts/2024/08/CVE-2024-3659 - Third Party Advisory
First Time Kaongroup ar2140
Kaongroup ar2140 Firmware
Kaongroup

08 Aug 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

08 Aug 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-08 13:15

Updated : 2025-11-17 17:15


NVD link : CVE-2024-3659

Mitre link : CVE-2024-3659

CVE.ORG link : CVE-2024-3659


JSON object : View

Products Affected

kaongroup

  • ar2140
  • ar2140_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')