First published: Fri Mar 07 2025(Updated: )
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QuRouter | <2.4.5.032 |
We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50390 is rated as a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2024-50390, upgrade to QuRouter version 2.4.5.032 or later.
Exploiting CVE-2024-50390 allows remote attackers to execute arbitrary commands on the affected systems.
CVE-2024-50390 affects QHora QuRouter versions before 2.4.5.032.
Yes, a patch is available in QuRouter version 2.4.5.032 and later to address CVE-2024-50390.