An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following versions:
QVR Firmware 5.0.0 and later
Conclusion & alert: CVE-2023-47565 is rated Critical Active Threat (90.5/100): CVSS High severity, with high exploitation likelihood (EPSS 86.75%, 99th percentile).Core evidence: CISA KEV confirms active exploitation (added 2023-12-21) affecting QNAP / VioStor NVR. a weakness (CWE-78) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit prediction scoring system (EPSS) score for CVE-2023-47565
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).