PT-2026-26633 · Qhora · Qhora

Published

2026-03-20

·

Updated

2026-03-30

·

CVE-2025-62843

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QHora versions prior to 2.6.3.009
Description An issue exists in QHora where an improper restriction of communication channels to intended endpoints can allow an attacker with physical access to gain elevated privileges. The issue was exploited as part of the Pwn2Own Ireland competition, resulting in root access when chained with other flaws.
Recommendations Update to QHora version 2.6.3.009 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-62843
ZDI-26-237

Affected Products

Qhora