CVE-2024-50389: QuRouter

9.5 CVSS

Description

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code.

We have already fixed the vulnerability in the following version:
QuRouter 2.4.5.032 and later

Classification

CVE ID: CVE-2024-50389

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.5

Affected Products

Vendor: QNAP Systems Inc.

Product: QuRouter

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.qnap.com/en/security-advisory/qsa-24-45

Timeline