CVE-2013-0144: QNAP VioStor Network Video Recorder

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.

Affected products

  • QNAP VioStor Network Video Recorder: version 4.0.3 only

Published 2013-06-07. Last modified 2026-06-16.