CVE-2025-62843

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:qnap:qurouter:2.6.0.239:build_20250625:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.0.688:build_20250818:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.1.028:build_20251001:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.2.007:build_20251027:*:*:*:*:*:*

History

14 Apr 2026, 14:19

Type Values Removed Values Added
Summary
  • (es) Se ha informado de una vulnerabilidad de restricción inadecuada del canal de comunicación a los puntos finales previstos que afecta a QHora. Si un atacante obtiene acceso físico, puede entonces explotar la vulnerabilidad para obtener los privilegios que estaban destinados al punto final original. Ya hemos corregido la vulnerabilidad en la siguiente versión: QuRouter 2.6.3.009 y posteriores
First Time Qnap
Qnap qurouter
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
References () https://www.qnap.com/en/security-advisory/qsa-26-12 - () https://www.qnap.com/en/security-advisory/qsa-26-12 - Vendor Advisory
CPE cpe:2.3:o:qnap:qurouter:2.6.2.007:build_20251027:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.0.688:build_20250818:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.1.028:build_20251001:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.0.239:build_20250625:*:*:*:*:*:*

20 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 17:16

Updated : 2026-06-17 09:52


NVD link : CVE-2025-62843

Mitre link : CVE-2025-62843

CVE.ORG link : CVE-2025-62843


JSON object : View

Products Affected

qnap

  • qurouter
CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints