ZDI-CAN-28424: ZDI-26-241: (Pwn2Own) QNAP QHora-322 qvpn_db_mgr username SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of QNAP QHora-322 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-62846.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28424?
ZDI-CAN-28424 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-28424?
To fix ZDI-CAN-28424, update your QNAP QHora-322 firmware to the latest version provided by QNAP.
What type of attack does ZDI-CAN-28424 enable?
ZDI-CAN-28424 enables remote attackers to execute arbitrary code on affected QNAP QHora-322 routers.
What permissions are required to exploit ZDI-CAN-28424?
Authentication is required to exploit the ZDI-CAN-28424 vulnerability, making it necessary for an attacker to have valid credentials.
Which devices are affected by ZDI-CAN-28424?
The ZDI-CAN-28424 vulnerability affects QNAP QHora-322 routers.