ZDI-CAN-25846: ZDI-26-244: (Pwn2Own) QNAP QHora-322 miro_webserver_controllers_api_login_singIn Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of QNAP QHora-322 routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2024-13088.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25846?
The severity of ZDI-CAN-25846 is high due to its potential for allowing unauthorized access to sensitive systems.
How do I fix ZDI-CAN-25846?
To fix ZDI-CAN-25846, update your QNAP QHora-322 firmware to the latest version provided by the vendor.
What is the impact of ZDI-CAN-25846?
The impact of ZDI-CAN-25846 is that it allows network-adjacent attackers to bypass authentication, leading to possible unauthorized control over the device.
Who is affected by ZDI-CAN-25846?
Users of the QNAP QHora-322 router are affected by ZDI-CAN-25846.
Is there a workaround for ZDI-CAN-25846?
Currently, no specific workarounds are recommended for ZDI-CAN-25846 apart from applying the firmware updates.