logo

Critical 9.3 CVSS Flaw in QNAP QVR Pro Exposes Surveillance Systems

ID: a0acec76-4a27-5944-9d4d-7443cb52ba0d

STIX ID: report--a0acec76-4a27-5944-9d4d-7443cb52ba0d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-21

Date Updated: 2026-04-23

Author: Ddos

...
...

QNAP has disclosed a critical authentication-bypass vulnerability (CVE-2026-22898, CVSS 9.3) in QVR Pro 2.7.x that allows remote attackers to bypass login and gain full access to surveillance systems, including live feeds and recorded footage. A patched release (QVR Pro 2.7.4.1485 and later) is available and administrators are urged to update immediately via QTS/QuTS hero App Center.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.