CVE-2025-62843: QuRouter
An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint.
We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62843?
CVE-2025-62843 is considered a significant vulnerability as it allows unauthorized endpoint access if an attacker gains physical access.
How do I fix CVE-2025-62843?
To fix CVE-2025-62843, update your QuRouter to version 2.6.3.009 or later.
What products are affected by CVE-2025-62843?
CVE-2025-62843 affects QuRouter versions prior to 2.6.3.009 and the QHora product.
Can CVE-2025-62843 be exploited remotely?
CVE-2025-62843 requires physical access to the device for exploitation, making remote attacks unlikely.
What are the potential consequences of CVE-2025-62843?
Exploitation of CVE-2025-62843 allows attackers to gain unauthorized privileges intended for the original endpoint.