QNAP QHora SQL Injection Vulnerability Allowing Unauthorized Code Execution

Vulnerability

A SQL injection vulnerability has been identified in QNAP's QuRouter version 2.6.x. This vulnerability allows local attackers with administrator privileges to execute unauthorized code or commands. The issue arises from improper validation of user input, which can be exploited to manipulate SQL queries and execute malicious payloads.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the affected device.

Remediation

Users can update to QuRouter version 2.6.3.009 or later to address this vulnerability. Instructions for updating QuRouter are available on the QNAP website.

Added: Mar 20, 2026, 5:22 PM
Updated: Mar 20, 2026, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.0
remediation
0.0
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.