ZDI-CAN-28422: ZDI-26-239: (Pwn2Own) QNAP QHora-322 login.newAuthMiddleware.Authenticator Authentication Bypass Vulnerability
Published Mar 30, 2026
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of QNAP QHora-322 routers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.6. The following CVEs are assigned: CVE-2025-62844.
Affected Software
1 affected component
QNAP QHora-322
Event History
Mar 30, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28422?
The severity of ZDI-CAN-28422 is critical due to its remote exploitation potential without authentication.
2
How do I fix ZDI-CAN-28422?
To fix ZDI-CAN-28422, update your QNAP QHora-322 router to the latest firmware version provided by QNAP.
3
What systems are affected by ZDI-CAN-28422?
ZDI-CAN-28422 affects QNAP QHora-322 routers specifically.
4
Who can exploit ZDI-CAN-28422?
Any remote attacker can exploit ZDI-CAN-28422 without needing authentication.
5
What type of vulnerability is ZDI-CAN-28422?
ZDI-CAN-28422 is an authentication bypass vulnerability.