ZDI-26-241: (Pwn2Own) QNAP QHora-322 qvpn_db_mgr username SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP QHora-322 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-62846.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-241?
The severity of ZDI-26-241 is rated at 8.8 on the CVSS scale.
How do I fix ZDI-26-241?
To address ZDI-26-241, update the QNAP QHora-322 to the latest firmware version provided by QNAP.
What does ZDI-26-241 exploit?
ZDI-26-241 exploits a SQL Injection vulnerability in the qvpn_db_mgr of QNAP QHora-322 routers.
Is authentication required to exploit ZDI-26-241?
Yes, authentication is required, but it can be bypassed due to the vulnerability.
What impact does ZDI-26-241 have on my system?
ZDI-26-241 allows remote attackers to execute arbitrary code, potentially compromising the entire system.