CVE-2025-52856: QNAP Qvr

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

Affected products

  • QNAP Qvr: from 5.1.0, before 5.1.6 (fixed in 5.1.6); version 5.1.6 only

Published 2025-08-29. Last modified 2026-06-17.