Unrated severityNVD Advisory· Published Jun 6, 2025· Updated Jun 6, 2025
QHora
CVE-2024-13088
Description
An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following version: QuRouter 2.5.0.140 and later
Affected products
2- QNAP Systems Inc./QuRouterv5Range: 2.5.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- ZDI-26-244: (Pwn2Own) QNAP QHora-322 miro_webserver_controllers_api_login_singIn Authentication Bypass VulnerabilityZero Day Initiative · Mar 30, 2026