ZDI-26-239: (Pwn2Own) QNAP QHora-322 login.newAuthMiddleware.Authenticator Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of QNAP QHora-322 routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.6. The following CVEs are assigned: CVE-2025-62844.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-239?
The severity of ZDI-26-239 is critical as it allows remote attackers to bypass authentication on QNAP QHora-322 routers.
How do I fix ZDI-26-239?
To fix ZDI-26-239, users should apply the latest firmware updates provided by QNAP for the QHora-322 router.
What versions of QNAP QHora-322 are affected by ZDI-26-239?
All versions of QNAP QHora-322 routers are affected by ZDI-26-239 as it exploits an authentication bypass vulnerability.
Can ZDI-26-239 be exploited remotely?
Yes, ZDI-26-239 can be exploited remotely without the need for authentication, making it particularly dangerous.
What types of attackers are targeted by the vulnerability ZDI-26-239?
ZDI-26-239 targets remote attackers who can exploit the vulnerability without needing any valid credentials.