QNAP QVR Pro Missing Authentication Vulnerability in Critical Function

Vulnerability

A vulnerability in QNAP QVR Pro versions 2.7.x has been identified, characterized by a missing authentication for critical functions. This flaw allows remote attackers to gain unauthorized access to the system. The vulnerability has been addressed in QVR Pro version 2.7.4.14 and later.

Impact

Exploitation of this vulnerability allows remote attackers to gain unauthorized access to the system.

Remediation

Users are advised to update QVR Pro to the latest version. Instructions for updating QVR Pro are available on the QNAP website.

Added: Mar 20, 2026, 5:20 PM
Updated: Mar 20, 2026, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
4.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.