PT-2026-26633 · Qhora · Qhora

Published

2026-03-20

·

Updated

2026-03-24

·

CVE-2025-62843

CVSS v4.0

0.9

Low

AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:U
Name of the Vulnerable Software and Affected Versions QHora versions prior to 2.6.3.009
Description An issue exists in QHora where an improper restriction of communication channels to intended endpoints can allow an attacker with physical access to gain elevated privileges. The issue was exploited as part of the Pwn2Own Ireland competition, resulting in root access when chained with other flaws.
Recommendations Update to QHora version 2.6.3.009 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-62843

Affected Products

Qhora