HostingTech@HostingTechNetPatch
QNAP has released patches for CVE-2025-62843 through CVE-2025-62846; the tweet provides no exploit or vulnerability details.
Cybersecurity News Everyday@TweetThreatNewsPatch
QNAP has issued patches for four critical SD‑WAN router CVEs identified at Pwn2Own Ireland 2025, covering QuNetSwitch and QVR Pro.
Infoflowcloud@infoflowcloudDisclosure
A new SQL injection vulnerability (CVE‑2025‑62846) affecting QHora is reported, noting that a local attacker with admin rights can exploit it to execute code. No PoC, exploit tools, patch information, or evidence of active exploitation is provided.
CVE@CVEnewDisclosure
Short notice announcing an SQL injection vulnerability in QHora that requires local admin access; no PoC, exploit, or patch info is provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2025-62846 as a SQL injection flaw in QHora Router that permits unauthorized code execution through the admin account.