Improper restriction of communication channel to intended endpoints in QuRouter - CVE-2025-62843
Published: March 23, 2026
Vulnerability identifier: #VU124215
CSH Severity: Low
CVSS v4: 4.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N]
CVE-ID: CVE-2025-62843
CWE-ID: CWE-923
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to improper restriction of communication channel to intended endpoints. An attacker with physical access can gain elevated privileges on the target system.
Affected software
QuRouter
How to mitigate CVE-2025-62843
Install updates from vendor's website.
QuRouter - update to 2.6.3.009