CVE-2025-62843Patch(qnap / qurouter)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch qnap qurouter systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-923

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qurouter

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-22); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
qurouter

4 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-22: 2Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-22: 203-2203-2303-2403-29
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-222
Disclosure1General1
2026-03-231
Patch1
2026-03-241
Patch1
2026-03-291
Patch1
Full discourse5 posts
  • HostingTech@HostingTechNet
    Patch

    QNAP patches vulnerabilities CVE-2025-62843 to CVE-2025-62846 https://hostingtech.net/qnap-patches-vulnerabilities-cve-2025-62843-to-cve-2025-62846/ via @HostingTech https://t.co/g75JBxNaqm

    Post summary

    QNAP has released patches for CVE-2025-62843 through CVE-2025-62846, as reported by @HostingTech.

    00070349
    121 followersView on X
  • Cyber Daily News@CyberDaily_News
    Patch

    QNAP patches four SD-WAN router flaws (CVE-2025-62843 through 62846) chained at Pwn2Own Ireland for root access - earned Team DDOS $100K. Update QuRouter to 2.6.3.009. Physical, LAN, and authenticated vectors all covered. https://securityaffairs.com/189871/security/qnap-fixed-four-vulnerabilities-demonstrated-at-pwn2own-ireland-2025.html #infosec #QNAP #Pwn2Own

    Post summary

    QNAP releases a patch for four SD‑WAN router vulnerabilities demonstrated at Pwn2Own Ireland, urging users to update to QuRouter version 2.6.3.009 to secure all physical, LAN, and authenticated vectors.

    01000182
    12 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    QNAP patches critical vulnerabilities including four SD-WAN router bugs showcased at Pwn2Own Ireland 2025 (CVE-2025-62843 to CVE-2025-62846). Fixes cover QuNetSwitch and QVR Pro. #QNAPSecurity #SDWAN #Ireland https://ift.tt/GW4BN0i

    Post summary

    QNAP released patches for four critical SD‑WAN router CVEs highlighted at Pwn2Own Ireland 2025, but the post does not include proof of concept details, exploit code, or evidence of active exploitation.

    00000167
    3.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-62843 An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can… https://www.cve.org/CVERecord?id=CVE-2025-62843 ----- Traducción: CVE-2025-62843 Una… http://infoflow.cloud`

    Post summary

    The text is a succinct disclosure of CVE‑2025‑62843 affecting QHora, offering minimal technical description and a link to the CVE record without indicating exploitation, patching, or a PoC.

    0000084
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-62843 An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can… https://www.cve.org/CVERecord?id=CVE-2025-62843

    Post summary

    A new CVE affecting QHora is reported, describing an improper restriction of communication channel to intended endpoints; no evidence of exploitation, PoC, or patch is disclosed.

    00000138
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSqnapqurouter2.6.0.239--
OSqnapqurouter2.6.0.688--
OSqnapqurouter2.6.1.028--
OSqnapqurouter2.6.2.007--

Explore more