ZeroHour

CVE-2023-47565

KEVlarge

Authenticated OS Command Injection in QNAP VioStor NVR (QVR Firmware 4.x)

CISA: QNAP VioStor NVR OS Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
73%p99
Published
()
KEV added
AI analysis

CVE-2023-47565 is an OS command injection vulnerability (CWE-78) affecting legacy QNAP VioStor NVR models running QVR Firmware 4.x, rated 8.8 (High) on the CVSS 3.1 scale. An authenticated user can send crafted input over the network that the device passes to the underlying operating system, triggering arbitrary command execution. Successful exploitation allows the attacker to run OS commands on the NVR, which typically means full compromise of the device for data access, lateral movement, or enrollment into botnets such as the Mirai-based InfectedSlurs campaign. Only organizations still operating legacy VioStor NVR hardware on QVR 4.x are affected; QNAP fixed the vulnerability in QVR Firmware 5.0.0 and later. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, EPSS assigns a 73.3% probability of exploitation within 30 days (99th percentile), and the InfectedSlurs botnet has been reported actively targeting it.

What to do: Upgrade affected legacy VioStor NVRs to QVR Firmware 5.0.0 or later; per CISA's KEV required action, apply vendor mitigations or discontinue use of any unit that cannot be updated. Remove internet exposure of the NVR web interface where possible, verify the running QVR firmware version on each device, and hunt for signs of botnet infection (unusual outbound traffic or processes) given confirmed in-the-wild exploitation.

Affected
QNAP VioStor NVR (QVR Firmware)QVR Firmware 4.x on legacy VioStor NVR models; fixed in QVR Firmware 5.0.0 and later
Estimated exposure
large≈tens of thousands of internet-exposed legacy VioStor NVR devices (estimate) — Estimated from public internet-scan visibility of legacy QNAP NVR web interfaces and the thousands-to-tens-of-thousands device scale of the InfectedSlurs/Mirai-based botnet campaign against QNAP VioStor units, since the exact installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later

CISA Known Exploited Vulnerability
Affected
QNAP VioStor NVR
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qnap
Products
qvr firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news