A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
2025-03-07T17:15:19.180
2025-09-24T20:32:59.580
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | qnap | qurouter | 2.4.0.190 | Yes |
| Operating System | qnap | qurouter | 2.4.1.172 | Yes |
| Operating System | qnap | qurouter | 2.4.1.634 | Yes |
| Operating System | qnap | qurouter | 2.4.2.317 | Yes |
| Operating System | qnap | qurouter | 2.4.2.538 | Yes |
| Operating System | qnap | qurouter | 2.4.3.103 | Yes |
| Operating System | qnap | qurouter | 2.4.4.106 | Yes |