PatchSiren cyber security CVE debrief
CVE-2025-63080 KAON CVE debrief
CVE-2025-63080 debrief: Authenticated users can send crafted JSON-RPC requests to KAON PG5298A and PG5298B routers, allowing operations not possible via GUI, such as system file reads or command execution. This vulnerability has been fixed in firmware versions 3.0.82 for PG5298A and 4.0.82 for PG5298B. The vulnerability allows for potential unauthorized system file reads and command execution with authenticated access. Defenders should prioritize verifying exposure, applying firmware updates, and monitoring for suspicious activity.
- Vendor
- KAON
- Product
- PG5298A
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-24
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-08-24
- Advisory updated
- 2026-09-29
Who should care
Defenders and administrators responsible for KAON PG5298A and PG5298B routers should assess exposure and apply necessary mitigations. This includes verifying exposure, applying firmware updates, and monitoring for suspicious activity. Additionally, security teams and vulnerability management teams should prioritize patching and monitoring for suspicious activity.
Why it matters
CVE-2025-63080 is a high-severity vulnerability in KAON PG5298A and PG5298B routers, allowing authenticated users to perform unauthorized actions via crafted JSON-RPC requests. Defenders should prioritize verifying exposure, applying firmware updates, and monitoring for suspicious activity.
- Potential unauthorized system file reads
- Potential command execution with authenticated access
- Verification of firmware versions and JSON-RPC access controls required
- Prioritization of patching and monitoring for suspicious activity
Technical summary
The vulnerability allows authenticated users to send crafted JSON-RPC requests to KAON PG5298A and PG5298B routers, enabling operations not possible via the GUI, such as system file reads or command execution. This is due to inadequate validation of JSON-RPC requests. The vulnerability has been addressed in firmware versions 3.0.82 for PG5298A and 4.0.82 for PG5298B. Defenders should prioritize verifying exposure of KAON PG5298A and PG5298B routers, checking for firmware updates, and restricting JSON-RPC access. The vulnerability has a high CVSS score of 8.5 and is considered a high-severity vulnerability.
Defensive priority
Defenders should prioritize verifying exposure of KAON PG5298A and PG5298B routers, checking for firmware updates, and restricting JSON-RPC access.
Recommended defensive actions
- Verify exposure of KAON PG5298A and PG5298B routers in the environment
- Check for and apply firmware updates to versions 3.0.82 for PG5298A and 4.0.82 for PG5298B
- Restrict JSON-RPC access to necessary users and systems
- Monitor for suspicious JSON-RPC requests and system activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected products, and fixed firmware versions. The vulnerability has been publicly disclosed and verified by the CVE Program and NIST NVD. There are no known instances of exploitation, but defenders should verify exposure and apply necessary mitigations. The evidence is limited to the provided CVE record and NVD entry, and further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-63080 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-63080
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-63080 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-63080
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cert.pl/en/posts/2026/08/CVE-2025-63080/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.