CVE-2024-13088: QHora
Published Jun 6, 2025
·Updated
An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later
Affected Software
10 affected components
QHora QuRouter<2.5.0.140
QNAP Qurouter=2.4.0.190-build_20240522
QNAP Qurouter=2.4.1.172-build_20240606
QNAP Qurouter=2.4.1.634-build_20240710
QNAP Qurouter=2.4.2.317-build_20240903
QNAP Qurouter=2.4.2.538-build_20240923
QNAP Qurouter=2.4.3.103-build_20241011
QNAP Qurouter=2.4.4.106-build_20241017
QNAP Qurouter=2.4.5.032-build_20241029
QNAP Qurouter=2.4.6.028-build_20250207
Remediation
Information
We have already fixed the vulnerability in the following version:
QuRouter 2.5.0.140 and later
Event History
Jun 6, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13088?
CVE-2024-13088 is an improper authentication vulnerability that can compromise system security if exploited.
2
How do I fix CVE-2024-13088?
To fix CVE-2024-13088, update your QHora QuRouter to version 2.5.0.1 or later.
3
What products are affected by CVE-2024-13088?
CVE-2024-13088 affects QHora QuRouter versions up to 2.5.0.140.
4
Can an attacker exploit CVE-2024-13088 remotely?
No, an attacker must have local network access to exploit CVE-2024-13088.
5
What are the potential impacts of CVE-2024-13088?
Exploitation of CVE-2024-13088 can lead to unauthorized access and potential compromise of the system's security.