CVE Vulnerabilities

CVE-2024-13088

Improper Authentication

Published: Jun 06, 2025 | Modified: Sep 24, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system.

We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
QurouterQnap2.4.0.190-build_20240522 (including)2.4.0.190-build_20240522 (including)
QurouterQnap2.4.1.172-build_20240606 (including)2.4.1.172-build_20240606 (including)
QurouterQnap2.4.1.634-build_20240710 (including)2.4.1.634-build_20240710 (including)
QurouterQnap2.4.2.317-build_20240903 (including)2.4.2.317-build_20240903 (including)
QurouterQnap2.4.2.538-build_20240923 (including)2.4.2.538-build_20240923 (including)
QurouterQnap2.4.3.103-build_20241011 (including)2.4.3.103-build_20241011 (including)
QurouterQnap2.4.4.106-build_20241017 (including)2.4.4.106-build_20241017 (including)
QurouterQnap2.4.5.032-build_20241029 (including)2.4.5.032-build_20241029 (including)
QurouterQnap2.4.6.028-build_20250207 (including)2.4.6.028-build_20250207 (including)

Potential Mitigations

References