QNAP QHora SQL Injection Vulnerability Allowing Unauthorized Code Execution
Vulnerability
A SQL injection vulnerability has been identified in QNAP's QuRouter version 2.6.x. This vulnerability allows local attackers with administrator privileges to execute unauthorized code or commands. The issue arises from improper validation of user input, which can be exploited to manipulate SQL queries and execute malicious payloads.
Impact
Exploitation of this vulnerability could lead to unauthorized code execution on the affected device.
Remediation
Users can update to QuRouter version 2.6.3.009 or later to address this vulnerability. Instructions for updating QuRouter are available on the QNAP website.
Added: Mar 20, 2026, 5:22 PM
Updated: Mar 20, 2026, 5:22 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
3.0remediation
0.0relevance
4.2threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
