CVE-2025-52856

Published Aug 29, 2025

Last updated 3 months ago

Overview

Description
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later
Source
security@qnapsecurity.com.tw
NVD status
Analyzed
Products
qvr

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@qnapsecurity.com.tw
CWE-287

Social media

Hype score
Not currently trending
  1. #VulnerabilityReport #CVE202552856 QNAP Patches Critical Flaw (CVE-2025-52856) with CVSS 9.3 https://t.co/6BYmJAGmAZ

    @Komodosec

    5 Oct 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨Dos vulnerabilidades críticas en QNAP ⚠️ CVE-2025-52856 ⚠️ CVE-2025-52861 https://t.co/XF5zIilEoS https://t.co/HfU8o5vbjb

    @elhackernet

    6 Sept 2025

    2879 Impressions

    7 Retweets

    15 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  3. QNAPのレガシーVioStor NVR(QVR 5.1.x以前)に、認証回避&パストラバーサル脆弱性(CVE-2025-52856、CVE-2025-52861)発見。管理者権限なしでも侵入可、サーバー内ファイルが丸見えに。最新QVR 5.1.6以降にアップデート必

    @Simplex_rm

    30 Aug 2025

    153 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. QNAPは2025年8月29日、旧型VioStor NVRシステムのQVR 5.1.xファームウェアに存在する2件の深刻な脆弱性に対し、修正版を公開した。 CVE-2025-52856は認証不備により不正ログインを許し、監視映像やシステム操作が外部

    @yousukezan

    30 Aug 2025

    801 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. QNAPは、古いVioStor NVRシステムのQVRファームウェアに影響を与える複数の脆弱性に対処するためのセキュリティパッチをリリースしました。重要な2つの脆弱性(CVE-2025-52856とCVE-2025-52861)が発見され、ユーザー

    @cyber_edu_jp

    30 Aug 2025

    63 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CRITICAL: QNAP VioStor 5.1.0 hit by improper authentication bug (CVE-2025-52856, CVSS 9.3)! Remote attackers could fully compromise surveillance systems. Patch to 5.1.6+ now! https://t.co/FIswocjxbS #OffSeq ... https://t.co/1ZUomM6X6z

    @offseq

    30 Aug 2025

    62 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. CVE-2025-52856 VioStor Remote Authentication Bypass Vulnerability in Versions Prior to 5.1.6 https://t.co/KQ5VCgfkYP

    @VulmonFeeds

    29 Aug 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-52856 An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security… https://t.co/cfVrv2UTVu

    @CVEnew

    29 Aug 2025

    222 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [CVE-2025-52856: CRITICAL] Critical authentication vulnerability in VioStor fixed in version 5.1.6 build 20250621. Ensure system security by updating to the latest version to prevent remote attacks.#cve,CVE-2025-52856,#cybersecurity https://t.co/gPpH6c0swX https://t.co/JfHCVCsBoV

    @CveFindCom

    29 Aug 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.