๐Ÿ” CVE Alert

CVE-2025-62843

UNKNOWN 0.0

QuRouter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
6th

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later

CWE CWE-923
Vendor qnap systems inc.
Product qurouter
Published Mar 20, 2026
Last Updated Mar 25, 2026
Stay Ahead of the Next One

Get instant alerts for qnap systems inc. qurouter

Be the first to know when new unknown vulnerabilities affecting qnap systems inc. qurouter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

QNAP Systems Inc. / QuRouter
2.6.x < 2.6.3.009

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
qnap.com: https://www.qnap.com/en/security-advisory/qsa-26-12

Credits

Pwn2Own 2025 - Team DDOS