Skip to main content

Vendor/product archive

qnap / qurouter CVEs

Beta · best-effort

12 CVEs tagged to qnap / qurouter2 Critical, 4 High, 4 Medium, 2 Low, 0 Unrated.

CVE-2025-62846

Published Mar 20, 2026

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthoriz…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-62845

Published Mar 20, 2026

An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62844

Published Mar 20, 2026

A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive informa…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62843

Published Mar 20, 2026

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit…

CVSS 0.9 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-29887

Published Aug 29, 2025

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13088

Published Jun 6, 2025

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the se…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13087

Published Jun 6, 2025

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-53700

Published Mar 7, 2025

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50390

Published Mar 7, 2025

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already f…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50389

Published Dec 6, 2024

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed t…

CVSS 9.5 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48861

Published Nov 22, 2024

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48860

Published Nov 22, 2024

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We h…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1