CVE-2025-62843

EUVD-2025-208895
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint.

We have already fixed the vulnerability in the following version:
QuRouter 2.6.3.009 and later
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
qnapqurouter
2.6.0.239:build_20250625
qnapqurouter
2.6.0.688:build_20250818
qnapqurouter
2.6.1.028:build_20251001
qnapqurouter
2.6.2.007:build_20251027
𝑥
= Vulnerable software versions