An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following version:
QuRouter 2.5.0.140 and later
References
Link | Resource |
---|---|
https://www.qnap.com/en/security-advisory/qsa-25-15 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
24 Sep 2025, 20:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.qnap.com/en/security-advisory/qsa-25-15 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
First Time |
Qnap
Qnap qurouter |
|
CPE | cpe:2.3:o:qnap:qurouter:2.4.1.172:build_20240606:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.2.538:build_20240923:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.6.028:build_20250207:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.2.317:build_20240903:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.4.106:build_20241017:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.0.190:build_20240522:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.3.103:build_20241011:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.5.032:build_20241029:*:*:*:*:*:* cpe:2.3:o:qnap:qurouter:2.4.1.634:build_20240710:*:*:*:*:*:* |
09 Jun 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
06 Jun 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-06 16:15
Updated : 2025-09-24 20:32
NVD link : CVE-2024-13088
Mitre link : CVE-2024-13088
CVE.ORG link : CVE-2024-13088
JSON object : View
Products Affected
qnap
- qurouter
CWE
CWE-287
Improper Authentication