安全ID : QSA-25-01

Vulnerability in QuRouter


  • 发布日期 : March 8, 2025

  • 通用漏洞披露 : CVE-2024-50390

  • 受影响产品: QuRouter 2.4.x

严重程度

Moderate

状态

已解决


Summary

A command injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands.

  

We have already fixed the vulnerability in the following version:

Affected Product Fixed Version
QuRouter 2.4.x QuRouter 2.4.5.032 and later

Recommendation

For optimal security and performance, we recommend regularly updating QuRouter to the latest version, ensuring you receive all vulnerability fixes and new features. You can view the product support status to check for the latest updates available for your model.

Updating QuRouter

  1. Log in to QuRouter.
  2. Go to Firmware.
  3. Select Update now.
  4. Select Latest.
  5. Click Apply.
    A confirmation message appears.
  6. Click Apply.
    QuRouter downloads and installs the latest firmware.

Tip: You can also download the latest firmware for your specific device from Download Center, and then perform a manual update in QuRouter by going to Firmware > Manual Update.

  

附件

致谢: Pwn2Own 2024 - Daan Keuper (@daankeuper), Thijs Alkemade, and Khaled Nassar from Computest Sector 7

修订历史:
V1.0 (March 8, 2025) - Published

选择规格

      显示更多 隐藏更多
      open menu
      back to top