CVE-2025-62845 describes an improper neutralization of escape, meta, or control sequences vulnerability (CWE-150) affecting QHora devices, fixed in QuRouter 2.6.3.009 and later. Rated Medium with a CVSSv4 score of 5.6, this local vulnerability requires an attacker to first gain administrator privileges to cause unexpected system behavior, potentially leading to high confidentiality impact on the device and high impact on subsequent systems. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0.239CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.0.239:build_20250625:*:*:*:*:*:* | ||
2.6.0.688CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.0.688:build_20250818:*:*:*:*:*:* | ||
2.6.1.028CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.1.028:build_20251001:*:*:*:*:*:* | ||
2.6.2.007CPE matchmatch criteria | cpe:2.3:o:qnap:qurouter:2.6.2.007:build_20251027:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.