CVE-2025-62846

Published Mar 20, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-62846 is an SQL injection vulnerability identified in QNAP QHora devices. This flaw allows a local attacker, who has already obtained administrator account credentials, to execute unauthorized code or commands on the affected system. This vulnerability was among several security issues in QNAP SD-WAN routers (CVE-2025-62843 to CVE-2025-62846) that were successfully demonstrated by Team DDOS at Pwn2Own Ireland 2025, where they chained multiple bugs to achieve root access.

Description
An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later
Source
security@qnapsecurity.com.tw
NVD status
Analyzed
Products
qurouter

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
6.7
Impact score
5.9
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

security@qnapsecurity.com.tw
CWE-89

Social media

Hype score
Not currently trending
  1. QNAP patches vulnerabilities CVE-2025-62843 to CVE-2025-62846 https://t.co/JIbGqsYZAO via @HostingTech https://t.co/g75JBxNaqm

    @HostingTechNet

    29 Mar 2026

    178 Impressions

    0 Retweets

    12 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. QNAPがSD-WANルータの脆弱性4件を修正。CVE-2025-62843からCVE-2025-62846。ハッキングコンテストPwn2Own 2025で悪用されたもの。 https://t.co/95unZS30oM

    @__kokumoto

    23 Mar 2026

    813 Impressions

    2 Retweets

    2 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  3. QNAP patches critical vulnerabilities including four SD-WAN router bugs showcased at Pwn2Own Ireland 2025 (CVE-2025-62843 to CVE-2025-62846). Fixes cover QuNetSwitch and QVR Pro. #QNAPSecurity #SDWAN #Ireland https://t.co/TsZcYIHdes

    @TweetThreatNews

    23 Mar 2026

    148 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨*CVE* CVE-2025-62846 An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execu… https://t.co/xoc64Bnrt1 ----- Traducción: CVE-2025-62846 Se … https://t.co/utmtNg

    @infoflowcloud

    22 Mar 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-62846 An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execu… https://t.co/BBYNRzQkcK

    @CVEnew

    22 Mar 2026

    123 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-62846 SQL Injection in QHora Router Enables Unauthorized Code Execution via Admin Account https://t.co/m7fMfxYmk5

    @VulmonFeeds

    20 Mar 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.