CVE-2025-52856 Details
Description
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later
An improper authentication vulnerability has been identified in QNAP VioStor NVR systems running QVR 5.1.x. This vulnerability allows remote attackers to compromise the security of the system. The issue has been resolved in VioStor version 5.1.6 build 20250621 and later.
Users are advised to update to VioStor version 5.1.6 build 20250621 or later. Instructions for updating the QVR firmware on legacy VioStor NVR can be found on the QNAP website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-29 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap qvr | >= 5.1.0, < 5.1.6 5.1.6 - |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | Initial Analysis | [email protected] |
| Aug 29, 2025 | New CVE Received | [email protected] |