PT-2026-26639 · Qnap · Qvr Pro

Fuzzinglabs

·

Published

2026-03-20

·

Updated

2026-04-15

·

CVE-2026-22898

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QVR Pro versions prior to 2.7.4.14
Description QVR Pro is affected by a missing authentication check for critical functions, allowing remote attackers to gain access to the system. The issue allows attackers to bypass authentication and access QVR Pro surveillance systems. The vulnerability has a CVSS score of 9.3, indicating a critical severity. It is described as a 'network-accessible goldmine for instant system compromise'. No information is available regarding the number of potentially affected devices or real-world exploitation incidents.
Recommendations Update QVR Pro to version 2.7.4.14 or later.

Fix

RCE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-22898
ZDI-26-292

Affected Products

Qvr Pro