Security ID : QSA-24-44

Multiple Vulnerabilities in QuRouter


  • Release date : November 23, 2024

  • CVE identifier : CVE-2024-48860 | CVE-2024-48861

  • Affected products: QuRouter 2.4.x

Severity

Important

Status

Resolved


Summary

Multiple vulnerabilities have been reported to affect QuRouter:

  • CVE-2024-48860, CVE-2024-48861: If exploited, the command injection vulnerabilities could allow remote attackers to execute arbitrary commands.

  

We have already fixed the vulnerabilities in the following version:

Affected Product Fixed Version
QuRouter 2.4.x QuRouter 2.4.3.106 and later

Recommendation

For optimal security and performance, we recommend regularly updating QuRouter to the latest version, ensuring you receive all vulnerability fixes and new features. You can view the product support status to check for the latest updates available for your model.

Updating QuRouter

  1. Log in to QuRouter.
  2. Go to Firmware.
  3. Select Update now.
  4. Select Latest.
  5. Click Apply.
    A confirmation message appears.
  6. Click Apply.
    QuRouter downloads and installs the latest firmware.

Tip: You can also download the latest firmware for your specific device from Download Center, and then perform a manual update in QuRouter by going to Firmware > Manual Update.

  

Attachment

Acknowledgements: Midnight Blue / PHP Hooligans

Revision History:
V1.0 (November 23, 2024) - Published

Choose specification

      Show more Less

      Choose Your Country or Region

      open menu
      back to top