Known vulnerabilities in QuRouter

Software: QuRouter
Software CPE: cpe:2.3:h:qnap_systems:qurouter:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting QuRouter QuRouter is affected by 11 known vulnerabilities: 3 high, 2 medium, 6 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124218 - Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2025-62845
CWE-150 Low
No
No
2.6.3.009 23.03.2026 SB2026032341
#VU124217 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-62846
CWE-89 Low
No
No
2.6.3.009 23.03.2026 SB2026032341
#VU124216 - Weak Authentication
CVE-2025-62844
CWE-1390 Medium
No
No
2.6.3.009 23.03.2026 SB2026032341
#VU124215 - Improper Restriction of Communication Channel to Intended Endpoints
CVE-2025-62843
CWE-923 Low
No
No
2.6.3.009 23.03.2026 SB2026032341
#VU114660 - Command injection
CVE-2025-29887
CWE-77 Low
No
No
2.5.1.060 02.09.2025 SB2025090228
#VU110667 - Improper Authentication
CVE-2024-13088
CWE-287 Medium
No
No
2.5.0.140 09.06.2025 SB2025060948
#VU110666 - Command injection
CVE-2024-13087
CWE-77 Low
No
No
2.5.0.140 09.06.2025 SB2025060948
#VU105456 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-50390
CWE-78 High
No
No
2.4.5.032 10.03.2025 SB2025031007
#VU105454 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-53700
CWE-78 Low
No
No
2.4.6.028 10.03.2025 SB2025031005
#VU100877 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-48861
CWE-78 High
No
No
2.4.3.106 25.11.2024 SB2024112516
#VU100876 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-48860
CWE-78 High
No
No
2.4.3.106 25.11.2024 SB2024112516