Command Injection Vulnerability in QHora from QNAP
CVE-2024-13087

2.4LOW

Key Information:

Vendor

QNAP

Status
Vendor
CVE Published:
6 June 2025

What is CVE-2024-13087?

A command injection vulnerability has been identified in QHora, allowing an attacker with local network access and admin credentials to execute arbitrary commands on the device. This poses significant risks if exploited, as it can lead to unauthorized actions within the network environment. Users are advised to update to version 2.4.6.028 or later to mitigate this risk effectively.

Affected Version(s)

QuRouter 2.4.x < 2.4.6.028

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team working with Trend Micro Zero Day Initiative
.