← Back

CVE-2024-13087

nvd nist
Published: Jun 6, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.4
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@qnapsecurity.com.tw (Secondary)

Description

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later

Affected (9)

Products: Qnap: Qurouter
1 product
Qurouter
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 2.4.0.190 build_20240522
Version 2.4.1.172 build_20240606
Version 2.4.1.634 build_20240710
Version 2.4.2.317 build_20240903
Version 2.4.2.538 build_20240923
Version 2.4.3.103 build_20241011
Version 2.4.4.106 build_20241017
Version 2.4.5.032 build_20241029
Version 2.4.6.028 build_20250207

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.