CVE-2025-62843 is an improper communication channel restriction vulnerability impacting QNAP QHora devices. It allows an attacker with physical access to the device to gain elevated privileges intended for legitimate endpoints. Despite a low CVSS score of 0.9 due to the physical access requirement, successful exploitation can lead to a high scope change. There is currently no evidence of active exploitation or public exploit code. QNAP has released a fix in QuRouter version 2.6.3.009 and later, with the vulnerability having been demonstrated at Pwn2Own Ireland 2025.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0.239CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.0.239:build_20250625:*:*:*:*:*:* | ||
2.6.0.688CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.0.688:build_20250818:*:*:*:*:*:* | ||
2.6.1.028CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.1.028:build_20251001:*:*:*:*:*:* | ||
2.6.2.007CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.2.007:build_20251027:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.