Critical QNAP QVR Pro Flaw Could Let Remote Attackers Access Systems
QNAP has issued a security advisory concerning a critical vulnerability in its QVR Pro application, a network video surveillance solution.
QNAP has issued a security advisory concerning a critical vulnerability in its QVR Pro application, a network video surveillance solution.
Announced on Mon, Mar 21, 2026, under advisory identifier QSA-26-07, this vulnerability allows unauthorized remote attackers to gain full access to affected systems. The vulnerability is identified as CVE-2026-22898 and is known as ZDI-CAN-28327.
Due to the sensitive nature of surveillance systems, it is imperative for administrators to apply the necessary patch to safeguard hardware infrastructure and broader network perimeters. The vulnerability was discovered and responsibly reported by FuzzingLabs.
The security issue arises from a missing authentication check on a critical function within the QVR Pro software architecture. This flaw allows attackers to bypass security checks and interact with the core system without valid credentials by sending crafted network requests. This vulnerability affects systems running QVR Pro 2.7.x.
QNAP has issued a security advisory concerning a critical vulnerability in its QVR Pro application, a network video surveillance solution.
The impact of exploitation extends beyond the surveillance application. An attacker gaining unauthorized access can potentially view surveillance feeds, alter camera configurations, or delete stored video archives. Given that QNAP devices often hold significant corporate data, a compromised system could serve as a gateway for further network infiltration, data theft, or ransomware deployment.
QNAP has addressed the vulnerability in the latest software update, and the flaw is marked as resolved. Users must upgrade to QVR Pro version 2.7.4.1485 or later to protect against remote attacks.
To update, administrators should log into the QTS or QuTS hero interface, access the App Center, find QVR Pro, and initiate the update. The system will automatically download and apply the secure release. If the update option is not available, the system is already secure.
Based on reporting by GBHackers.
