QuTScloud

QuTScloud is the operating system for QNAP Cloud NAS virtual appliances. With the possibility of on-premises and cloud deployment, QuTScloud enables optimized cloud data usage and flexible resource allocation at a predictable monthly cost.

System
Applications

QES

QES is the operating system for dual-controller QNAP NAS models. With FreeBSD and ZFS, QES is flash-optimized, capable of driving outstanding performance for all-flash storage arrays.

System
Product
Resources

QNE Network

QNE Network is the operating system for QuCPE, QNAP's universal customer premises equipment series. Run virtual network functions, freely configure software-defined networks, and enjoy benefits such as lowered costs and reduced management efforts.

System
Applications

QSS

QNAP Switch System (QSS) is the configuration interface for QNAP's managed switch series. Enable management functions such as link aggregation, VLAN, and RSTP, to take care of your network topology with ease.

System

QuRouter

QNAP’s QuRouter OS simplifies managing high-speed and high-coverage LAN/WAN. With NAT, VPN, security, and QuWAN SD-WAN, network management is made easier and remote connections more secure.

System
Applications

QVR Surveillancee

QVR Surveillance is QNAP’s network video recorder software solution. It offers subscription-based QVR Elite and perpetual QVR Pro, and can be used with a series of apps, such as face recognition and door access control for a wider range of scenarios.

System
Applications
Resources

QVR Face

QVR Face is a smart facial recognition solution featuring real-time live streaming video analytics from connected cameras. It can be integrated into multiple scenarios to provide intelligent attendance management, door access control management, VIP welcome systems and smart retail services.

System
Applications
Resources

KoiMeeter

QNAP smart video solutions provides integrated intelligent packages such as video conferencing and smart retail, boosting productivity for individuals and businesses.

Video Conferencing
Smart Retail

Security ID : QSA-23-48

Vulnerability Affecting Legacy VioStor NVR


  • Release date : December 9, 2023

  • CVE identifier : CVE-2023-47565

  • Affected products: QVR Firmware 4.x

Severity

High

Status

Resolved


Summary

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network.

We have already fixed the vulnerability in QVR Firmware 5.0.0 on June 21, 2014:

  

Affected Product Fixed Version
QVR Firmware 4.x QVR Firmware 5.x and later

Recommendation

To mitigate the vulnerability, ensure you apply strong passwords for all user accounts.

To further secure your device, we highly recommend updating QVR to the latest version.

Changing User Passwords in QVR

  1. Log on to QVR.
  2. Go to Control Panel > Privilege > Users.
  3. Identify the user you want to edit.
    Note: Only administrators can change the passwords of other users.
  4. Click the Change Password icon.
  5. Specify a new, strong password.
  6. Verify the password.
  7. Click Apply.

Updating QVR Firmware

  1. Log on to QVR as an administrator.
  2. Go to Control Panel > System Settings > Firmware Update.
  3. Select the Firmware Update tab.
  4. Click Browse... to upload the latest firmware file.
    Tip: Download the latest firmware file for your specific model from https://www.qnap.com/go/download. Select "Legacy NVR" to locate your model.
  5. Click Update System.
    QVR installs the update.

  

Attachment

Acknowledgements: Chad Seaman and Larry Cashdollar of Akamai Technologies reported this vulnerability to CISA.

Revision History:
V1.0 (December 09, 2023) - Published

Choose specification

      Show more Less

      Choose Your Country or Region

      open menu
      back to top