ZDI-CAN-28371: ZDI-26-237: (Pwn2Own) QNAP QHora-322 ip6_wanifset Improper Restriction of Communication Channel to Intended Endpoints Firewall Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of QNAP QHora-322 routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2025-62843.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28371?
ZDI-CAN-28371 has a CVSS rating of 6.3, indicating a medium-severity vulnerability.
How do I fix ZDI-CAN-28371?
To mitigate ZDI-CAN-28371, ensure that you apply the latest firmware update for the QNAP QHora-322.
Who is impacted by ZDI-CAN-28371?
ZDI-CAN-28371 affects installations of the QNAP QHora-322 routers that have not been updated.
What type of vulnerability is ZDI-CAN-28371?
ZDI-CAN-28371 is described as an improper restriction of communication channel to intended endpoints, leading to firewall bypass.
Is authentication required to exploit ZDI-CAN-28371?
No, authentication is not required to exploit the ZDI-CAN-28371 vulnerability.