Security ID : QSA-25-15

Multiple Vulnerabilities in QuRouter


  • Release date : June 7, 2025

  • CVE identifier : CVE-2024-13087 | CVE-2024-13088

  • Affected products: QuRouter 2.4.x, 2.5.x

Severity

Moderate

Status

Resolved


Summary

Multiple vulnerabilities have been reported to affect QuRouter:

  • CVE-2024-13087: Command injection vulnerability
    If an attacker gains access to the local network and also to an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
  • CVE-2024-13088: Improper authentication vulnerability
    If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system.

  

We have already fixed the vulnerabilities in the following version:

Affected Product Fixed Version
QuRouter 2.4.x and 2.5.x QuRouter 2.5.0.140 and later

Recommendation

For optimal security and performance, we recommend regularly updating QuRouter to the latest version, ensuring you receive all vulnerability fixes and new features. You can view the product support status to check for the latest updates available for your model.

Updating QuRouter

  1. Log in to QuRouter.
  2. Go to Firmware.
  3. Select Update now.
  4. Select Latest.
  5. Click Apply.
    A confirmation message appears.
  6. Click Apply.
    QuRouter downloads and installs the latest firmware.

Tip: You can also download the latest firmware for your specific device from Download Center, and then perform a manual update in QuRouter by going to Firmware > Manual Update.

  

Attachment

Acknowledgements: nella17 (@nella17tw), working with DEVCORE Internship Program, and DEVCORE Research Team working with Trend Micro Zero Day Initiative

Revision History:
V1.0 (June 07, 2025) - Published

仕様を選択

      もっと見る 閉じる

      当ページを他の国/地域で見る:

      気軽にお問い合わせ! show inquiry button
      open menu
      back to top