PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-63080 KAON CVE debrief

CVE-2025-63080 debrief: Authenticated users can send crafted JSON-RPC requests to KAON PG5298A and PG5298B routers, allowing operations not possible via GUI, such as system file reads or command execution. This vulnerability has been fixed in firmware versions 3.0.82 for PG5298A and 4.0.82 for PG5298B. The vulnerability allows for potential unauthorized system file reads and command execution with authenticated access. Defenders should prioritize verifying exposure, applying firmware updates, and monitoring for suspicious activity.

Vendor
KAON
Product
PG5298A
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-24
Original CVE updated
2026-09-29
Advisory published
2026-08-24
Advisory updated
2026-09-29

Who should care

Defenders and administrators responsible for KAON PG5298A and PG5298B routers should assess exposure and apply necessary mitigations. This includes verifying exposure, applying firmware updates, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should prioritize patching and monitoring for suspicious activity.

Why it matters

CVE-2025-63080 is a high-severity vulnerability in KAON PG5298A and PG5298B routers, allowing authenticated users to perform unauthorized actions via crafted JSON-RPC requests. Defenders should prioritize verifying exposure, applying firmware updates, and monitoring for suspicious activity.

  • Potential unauthorized system file reads
  • Potential command execution with authenticated access
  • Verification of firmware versions and JSON-RPC access controls required
  • Prioritization of patching and monitoring for suspicious activity

Technical summary

The vulnerability allows authenticated users to send crafted JSON-RPC requests to KAON PG5298A and PG5298B routers, enabling operations not possible via the GUI, such as system file reads or command execution. This is due to inadequate validation of JSON-RPC requests. The vulnerability has been addressed in firmware versions 3.0.82 for PG5298A and 4.0.82 for PG5298B. Defenders should prioritize verifying exposure of KAON PG5298A and PG5298B routers, checking for firmware updates, and restricting JSON-RPC access. The vulnerability has a high CVSS score of 8.5 and is considered a high-severity vulnerability.

Defensive priority

Defenders should prioritize verifying exposure of KAON PG5298A and PG5298B routers, checking for firmware updates, and restricting JSON-RPC access.

Recommended defensive actions

  • Verify exposure of KAON PG5298A and PG5298B routers in the environment
  • Check for and apply firmware updates to versions 3.0.82 for PG5298A and 4.0.82 for PG5298B
  • Restrict JSON-RPC access to necessary users and systems
  • Monitor for suspicious JSON-RPC requests and system activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected products, and fixed firmware versions. The vulnerability has been publicly disclosed and verified by the CVE Program and NIST NVD. There are no known instances of exploitation, but defenders should verify exposure and apply necessary mitigations. The evidence is limited to the provided CVE record and NVD entry, and further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-63080 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-63080

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-63080 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-63080

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.