CVE-2025-62844

A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:qnap:qurouter:2.6.0.239:build_20250625:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.0.688:build_20250818:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.1.028:build_20251001:*:*:*:*:*:*

History

14 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Se ha reportado una vulnerabilidad de autenticación débil que afecta a QHora. Si un atacante obtiene acceso a la red local, puede entonces explotar la vulnerabilidad para obtener información sensible. Ya hemos corregido la vulnerabilidad en la siguiente versión: QuRouter 2.6.2.007 y posteriores
First Time Qnap
Qnap qurouter
References () https://www.qnap.com/en/security-advisory/qsa-26-12 - () https://www.qnap.com/en/security-advisory/qsa-26-12 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:qnap:qurouter:2.6.0.688:build_20250818:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.1.028:build_20251001:*:*:*:*:*:*
cpe:2.3:o:qnap:qurouter:2.6.0.239:build_20250625:*:*:*:*:*:*

20 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 17:16

Updated : 2026-06-17 09:52


NVD link : CVE-2025-62844

Mitre link : CVE-2025-62844

CVE.ORG link : CVE-2025-62844


JSON object : View

Products Affected

qnap

  • qurouter
CWE
CWE-1390

Weak Authentication