Executive brief
An OS command injection vulnerability in legacy QNAP VioStor NVR models running QVR Firmware 4.x allows authenticated users to execute arbitrary commands via the network. The vulnerability was addressed in QVR Firmware version 5.0.0 and later.
Affected products
- QNAP Systems, Inc. QVR Firmware 4.x (specifically 4.0.0 up to but excluding 5.0.0)
- QNAP Systems, Inc. VioStor NVR
Timeline
- 2023-12-08: disclosed: Initial disclosure by QNAP Systems, Inc.
- 2023-12-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2023-12-21: exploited: Reported as exploited in the wild.
- 2024-01-11: other: CISA KEV remediation due date.