Improper Neutralization Vulnerability in QHora by QNAP
CVE-2025-62845
5.6MEDIUM
What is CVE-2025-62845?
An improper neutralization of escape, meta, or control sequences vulnerability in QHora can allow a local attacker with administrator access to exploit the flaw. This can lead to unexpected behaviors within the system, potentially giving the attacker control over the application's operations. It's pivotal that users update to QRouter version 2.6.3.009 or later to mitigate this risk effectively.
Affected Version(s)
QuRouter 2.6.x < 2.6.3.009