Loading
An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later
Cite this page
CVE-2025-62846. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-62846
Use CWE-89, Qnap vendor hub and Qurouter product page to widen CVE-2025-62846 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-50389, CVE-2024-48860 and CVE-2024-50390 for nearby disclosures in the same product family.