CVE-2025-62846 Details
Description
An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later
A SQL injection vulnerability has been identified in QNAP's QuRouter version 2.6.x. This vulnerability allows local attackers with administrator privileges to execute unauthorized code or commands. The issue arises from improper validation of user input, which can be exploited to manipulate SQL queries and execute malicious payloads.
Users can update to QuRouter version 2.6.3.009 or later to address this vulnerability. Instructions for updating QuRouter are available on the QNAP website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-12 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap qurouter | 2.6.0.239 build_20250625 2.6.0.688 build_20250818 2.6.1.028 build_20251001 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Mar 20, 2026 | New CVE Received | [email protected] |