CVE-2023-47565
KEVlargeAuthenticated OS Command Injection in QNAP VioStor NVR (QVR Firmware 4.x)
CISA: QNAP VioStor NVR OS Command Injection Vulnerability
CVE-2023-47565 is an OS command injection vulnerability (CWE-78) affecting legacy QNAP VioStor NVR models running QVR Firmware 4.x, rated 8.8 (High) on the CVSS 3.1 scale. An authenticated user can send crafted input over the network that the device passes to the underlying operating system, triggering arbitrary command execution. Successful exploitation allows the attacker to run OS commands on the NVR, which typically means full compromise of the device for data access, lateral movement, or enrollment into botnets such as the Mirai-based InfectedSlurs campaign. Only organizations still operating legacy VioStor NVR hardware on QVR 4.x are affected; QNAP fixed the vulnerability in QVR Firmware 5.0.0 and later. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, EPSS assigns a 73.3% probability of exploitation within 30 days (99th percentile), and the InfectedSlurs botnet has been reported actively targeting it.
What to do: Upgrade affected legacy VioStor NVRs to QVR Firmware 5.0.0 or later; per CISA's KEV required action, apply vendor mitigations or discontinue use of any unit that cannot be updated. Remove internet exposure of the NVR web interface where possible, verify the running QVR firmware version on each device, and hunt for signs of botnet infection (unusual outbound traffic or processes) given confirmed in-the-wild exploitation.
| QNAP VioStor NVR (QVR Firmware) | QVR Firmware 4.x on legacy VioStor NVR models; fixed in QVR Firmware 5.0.0 and later |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later
- Affected
- QNAP VioStor NVR
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qnap
- Products
- qvr firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H