CVE-2024-50390
published 2025-03-07CVE-2024-50390: A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary…
high7.7CVSS 4.0
AVNACLATPPRNUIPVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.
We have already fixed the vulnerability in the following version:
QuRouter 2.4.5.032 and later
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | qurouter | — | — |
| qnap | qurouter | — | — |
| qnap | qurouter | — | — |
| qnap | qurouter | — | — |
| qnap | qurouter | — | — |
| qnap | qurouter | — | — |
| qnap | qurouter | — | — |
| qnap_systems_inc | qurouter | >= 2.4.x < 2.4.5.032 | 2.4.5.032 |