CVE-2024-48861: QHora
Published Nov 22, 2024
·Updated
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands.
We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later
Affected Software
7 affected components
QuRouter QuRouter<2.4.4.106
QNAP Qurouter=2.4.0.190-build_20240522
QNAP Qurouter=2.4.1.172-build_20240606
QNAP Qurouter=2.4.1.634-build_20240710
QNAP Qurouter=2.4.2.317-build_20240903
QNAP Qurouter=2.4.2.538-build_20240923
QNAP Qurouter=2.4.3.103-build_20241011
Remediation
Information
We have already fixed the vulnerability in the following versions:
QuRouter 2.4.4.106 and later
Event History
Nov 22, 2024
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 25, 2024
News Published
via BleepingComputer·10:13 PM
News Published
via BleepingComputer·10:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-48861?
CVE-2024-48861 is considered a critical OS command injection vulnerability.
2
How do I fix CVE-2024-48861?
To fix CVE-2024-48861, update to QuRouter version 2.4.4.106 or later.
3
Who is affected by CVE-2024-48861?
CVE-2024-48861 affects QuRouter versions prior to 2.4.4.106.
4
What could happen if CVE-2024-48861 is exploited?
Exploitation of CVE-2024-48861 could allow local network attackers to execute arbitrary commands.
5
Is there a workaround for CVE-2024-48861?
There are no specific workarounds for CVE-2024-48861; upgrading to a secure version is recommended.