PT-2024-7609 · Qurouter · Qurouter

Published

2024-10-29

·

Updated

2025-08-13

·

CVE-2024-50389

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QuRouter versions prior to 2.4.5.032
Description A SQL injection vulnerability has been reported to affect QuRouter, allowing remote attackers to inject malicious code if exploited. The vulnerability is related to errors in processing input data, which could enable a remote attacker to execute arbitrary code. The issue was exploited during the Pwn2Own hacking contest, indicating real-world exploitation.
Recommendations For QuRouter versions prior to 2.4.5.032, update to version 2.4.5.032 or later to prevent remote attacks injecting malicious code. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied.

Fix

SQL injection

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-08774
BDU:2024-09015
CVE-2024-50389
ZDI-25-741

Affected Products

Qurouter