CVE-2025-29887: QNAP Qurouter
High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuRouter 2.5.1.060 and later
Affected products
- QNAP Qurouter: version 2.5.0.140 only; version 2.5.0.268 only
Published 2025-08-29. Last modified 2026-06-17.