PT-2026-26639 · Qnap · Qvr Pro
Fuzzinglabs
·
Published
2026-03-20
·
Updated
2026-04-15
·
CVE-2026-22898
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QVR Pro versions prior to 2.7.4.14
Description
QVR Pro is affected by a missing authentication check for critical functions, allowing remote attackers to gain access to the system. The issue allows attackers to bypass authentication and access QVR Pro surveillance systems. The vulnerability has a CVSS score of 9.3, indicating a critical severity. It is described as a 'network-accessible goldmine for instant system compromise'. No information is available regarding the number of potentially affected devices or real-world exploitation incidents.
Recommendations
Update QVR Pro to version 2.7.4.14 or later.
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qvr Pro