ZDI-26-237: (Pwn2Own) QNAP QHora-322 ip6_wanifset Improper Restriction of Communication Channel to Intended Endpoints Firewall Bypass Vulnerability
Published Mar 30, 2026
·Updated
This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of QNAP QHora-322 routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2025-62843.
Affected Software
1 affected component
QNAP QHora-322
Event History
Mar 30, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-237?
The severity of ZDI-26-237, as assigned by the ZDI, is a CVSS rating of 6.3.
2
How do I fix ZDI-26-237?
To fix ZDI-26-237, ensure you update your QNAP QHora-322 router to the latest firmware provided by QNAP.
3
What type of devices are affected by ZDI-26-237?
ZDI-26-237 affects QNAP QHora-322 routers specifically.
4
Can ZDI-26-237 be exploited remotely?
Yes, ZDI-26-237 allows network-adjacent attackers to exploit the vulnerability without authentication.
5
What does ZDI-26-237 allow attackers to do?
ZDI-26-237 allows attackers to bypass firewall rules on vulnerable QNAP QHora-322 routers.