An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands.
We have already fixed the vulnerability in the following versions:
QuRouter 2.4.4.106 and later
CVE ID: CVE-2024-48861
CVSS Base Severity: HIGH
CVSS Base Score: 7.3
Vendor: QNAP Systems Inc.
Product: QuRouter
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.72% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)