An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later
Cite this page
CVE-2025-62843. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-62843
Use CWE-923, Qnap vendor hub and Qurouter product page to widen CVE-2025-62843 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-50389, CVE-2024-48860 and CVE-2024-50390 for nearby disclosures in the same product family.