CVE-2025-62846: QuRouter
An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62846?
CVE-2025-62846 is categorized as a high severity SQL injection vulnerability affecting the QHora device.
How do I fix CVE-2025-62846?
To fix CVE-2025-62846, update your QHora or QuRouter software to version 2.6.2.007 or later.
Who is affected by CVE-2025-62846?
CVE-2025-62846 affects users of QHora and QuRouter devices running versions prior to 2.6.2.007.
Can CVE-2025-62846 allow unauthorized access?
Yes, if exploited, CVE-2025-62846 can allow a local attacker with an administrator account to execute unauthorized code.
Is there a patch available for CVE-2025-62846?
Yes, a patch is available in version 2.6.2.007 of QHora and QuRouter to mitigate CVE-2025-62846.