PatchSiren

KAON CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH KAON CVE published 2026-08-24

CVE-2025-63080

CVE-2025-63080 debrief: Authenticated users can send crafted JSON-RPC requests to KAON PG5298A and PG5298B routers, allowing operations not possible via GUI, such as system file reads or command execution. This vulnerability has been fixed in firmware versions 3.0.82 for PG5298A and 4.0.82 for PG5298B. The vulnerability allows for potential unauthorized system file reads and command execution with authent [truncated]