A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later
History

Fri, 07 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.6.028 and later
Title QHora
Weaknesses CWE-77
CWE-78
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2025-03-07T17:52:31.620Z

Reserved: 2024-11-22T06:21:49.207Z

Link: CVE-2024-53700

cve-icon Vulnrichment

Updated: 2025-03-07T17:52:28.098Z

cve-icon NVD

Status : Received

Published: 2025-03-07T17:15:20.957

Modified: 2025-03-07T17:15:20.957

Link: CVE-2024-53700

cve-icon Redhat

No data.