Command Injection Vulnerability in QuRouter by QNAP
CVE-2025-29887

7.1HIGH

Key Information:

Vendor

QNAP

Status
Vendor
CVE Published:
29 August 2025

What is CVE-2025-29887?

A command injection flaw has been identified in QuRouter version 2.5.1, permitting remote attackers with administrative access to exploit the vulnerability and run arbitrary commands within the system. It is crucial to update to version 2.5.1.060 or later to mitigate the risk associated with this vulnerability.

Affected Version(s)

QuRouter 2.5.x < 2.5.1.060

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous
.