Home
MEDIUM: 4.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:UDefault status
unaffected
2.6.x (custom) before 2.6.2.007
affected
Description
A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later
Problem types
Product status
2.6.x (custom) before 2.6.2.007
Credits
Pwn2Own 2025 - Team DDOS
References
www.qnap.com/en/security-advisory/qsa-26-12