CVE-2025-62846Disclosure(qnap / qurouter)

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch qnap qurouter systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qurouter

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-22); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
qurouter

3 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-03-23: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 203-2003-2203-2303-29
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-222
Disclosure2
2026-03-231
Patch1
2026-03-291
Patch1
Full discourse5 posts
  • HostingTech@HostingTechNet
    Patch

    QNAP patches vulnerabilities CVE-2025-62843 to CVE-2025-62846 https://hostingtech.net/qnap-patches-vulnerabilities-cve-2025-62843-to-cve-2025-62846/ via @HostingTech https://t.co/g75JBxNaqm

    Post summary

    QNAP has released patches for CVE-2025-62843 through CVE-2025-62846; the tweet provides no exploit or vulnerability details.

    00070349
    121 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    QNAP patches critical vulnerabilities including four SD-WAN router bugs showcased at Pwn2Own Ireland 2025 (CVE-2025-62843 to CVE-2025-62846). Fixes cover QuNetSwitch and QVR Pro. #QNAPSecurity #SDWAN #Ireland https://ift.tt/GW4BN0i

    Post summary

    QNAP has issued patches for four critical SD‑WAN router CVEs identified at Pwn2Own Ireland 2025, covering QuNetSwitch and QVR Pro.

    00000167
    3.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-62846 An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execu… https://www.cve.org/CVERecord?id=CVE-2025-62846 ----- Traducción: CVE-2025-62846 Se … http://infoflow.cloud`

    Post summary

    A new SQL injection vulnerability (CVE‑2025‑62846) affecting QHora is reported, noting that a local attacker with admin rights can exploit it to execute code. No PoC, exploit tools, patch information, or evidence of active exploitation is provided.

    0000089
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-62846 An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execu… https://www.cve.org/CVERecord?id=CVE-2025-62846

    Post summary

    Short notice announcing an SQL injection vulnerability in QHora that requires local admin access; no PoC, exploit, or patch info is provided.

    00000138
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-62846 SQL Injection in QHora Router Enables Unauthorized Code Execution via Admin Account https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-62846

    Post summary

    The text announces CVE-2025-62846 as a SQL injection flaw in QHora Router that permits unauthorized code execution through the admin account.

    0000089
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSqnapqurouter2.6.0.239--
OSqnapqurouter2.6.0.688--
OSqnapqurouter2.6.1.028--

Explore more