HIGH

CVE-2023-47565

Qnap Qvr Firmware 2023-12-08 CVSS v3.1
CVSS
8.8
KEV

Description

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.

We have already fixed the vulnerability in the following versions:

QVR Firmware 5.0.0 and later

Summary dbcve.org

OS command injection vulnerability in legacy QNAP VioStor NVR devices running QVR Firmware 4.x allows authenticated users to execute arbitrary OS commands via network, likely due to insufficient input sanitization in web interface parameters.

Mitigation

Upgrade affected VioStor NVR devices to QVR Firmware 5.0.0 or later. If upgrades are not possible, restrict administrative access to trusted IP addresses and monitor for suspicious command execution.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

73.28%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE