During the Pwn2Own Ireland 2025 event, the research team 'Team DDOS' successfully demonstrated a chain of vulnerabilities in QNAP SD-WAN routers. These vulnerabilities, tracked as CVE-2025-62843, CVE-2025-62844, CVE-2025-62845, and CVE-2025-62846, allowed the researchers to bypass security controls and gain root access to the devices. QNAP has since issued firmware updates to remediate these security gaps.
SD-WAN devices are critical components of modern enterprise network architecture, often serving as the gateway between internal networks and the internet. Successful exploitation of these devices provides attackers with a strategic foothold for lateral movement, data theft, and network disruption. Because these vulnerabilities were publicly demonstrated at a major security event, the window for threat actors to develop and deploy exploit code is significantly narrowed.
Advisory purposes only · QPulse Security Intelligence Platform · 2026 · Brief #00414