Vulnerability Database

308,820

Total vulnerabilities in the database

CVE-2024-48861

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands.

We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

  • Published: Nov 22, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-48861
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Software From Fixed in
qnap / qurouter 2.4.0.190-build_20240522 2.4.0.190-build_20240522.x
qnap / qurouter 2.4.1.172-build_20240606 2.4.1.172-build_20240606.x
qnap / qurouter 2.4.1.634-build_20240710 2.4.1.634-build_20240710.x
qnap / qurouter 2.4.2.317-build_20240903 2.4.2.317-build_20240903.x
qnap / qurouter 2.4.2.538-build_20240923 2.4.2.538-build_20240923.x
qnap / qurouter 2.4.3.103-build_20241011 2.4.3.103-build_20241011.x