An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later
2024-11-22T16:15:28.483
2025-09-24T19:10:13.737
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | qnap | qurouter | 2.4.0.190 | Yes |
| Operating System | qnap | qurouter | 2.4.1.172 | Yes |
| Operating System | qnap | qurouter | 2.4.1.634 | Yes |
| Operating System | qnap | qurouter | 2.4.2.317 | Yes |
| Operating System | qnap | qurouter | 2.4.2.538 | Yes |
| Operating System | qnap | qurouter | 2.4.3.103 | Yes |