EUVD-2023-51676
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 21 Dec 2023. Evidence sources: cisa_kev.
- ENISA score
- 8.0 · CVSS 3.1
- Advisory evidence
- 1 linked advisory record
