QNAP QHora Improper Authentication Vulnerability

Vulnerability

A vulnerability allowing improper authentication has been identified in QNAP's QuRouter, specifically in versions 2.4.x and 2.5.x. This vulnerability can be exploited by an attacker with local network access to compromise the security of the system.

Impact

Exploitation of this vulnerability can lead to a general compromise of the system's security.

Remediation

Users can update to QuRouter version 2.5.0.140 or later to address this vulnerability. Instructions for updating QuRouter are available on the QNAP website.

Added: Jun 6, 2025, 4:38 PM
Updated: Jun 6, 2025, 4:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
7.7
relevance
0.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.