PT-2025-24288 · Qhora+1 · Qhora+1

Published

2025-06-06

·

Updated

2025-09-24

·

CVE-2024-13087

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QuRouter versions prior to 2.4.6.028
Description A command injection issue has been reported, affecting QHora. An attacker with local network access and an administrator account can exploit this to execute arbitrary commands.
Recommendations For versions prior to 2.4.6.028, update to QuRouter version 2.4.6.028 or later to resolve the issue.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13087
ZDI-25-871

Affected Products

Qhora
Qurouter