PULSE
FEED
ransomqilin reclama a Arnold Center · US · Not Foundransomincransom reclama a bakemyday.se · SE · Retail & E-Commerceransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomqilin reclama a Arnold Center · US · Not Foundransomincransom reclama a bakemyday.se · SE · Retail & E-Commerceransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Services
← Todos los CVEs
CVE Watch28 sept 2026

CVE-2026-52749

The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 28 sept 2026 · Última mod.: 28 sept 2026 · CWE-287

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-10107710.0 CRÍ
—
———A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.9h
CVE-2026-1010738.3 ALT
—
———A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.10h
CVE-2026-1010045.3 MED
—
———A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely. Versions 4.1.0 - 4.9.5.2 allow unauthenticated exploitation due to missing method check. In versions 4.9.5.7 - 4.10.10 a guard present but only enforced when CACHE_REVALIDATION_TOKEN is set. Default deployments remain unprotected. The vendor was contacted early about this disclosure but did not respond in any way.10h
CVE-2026-1009035.3 MED
—
———A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."10h
CVE-2026-10088610.0 CRÍ
—
——0A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.10h
CVE-2026-1008766.3 MED
—
——0A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.10h