CVE-2025-52856
CRITICAL WAF: Low
CVSS 9.8
Published: 2025-08-29
CWE-287
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later
WAF Coverage Analysis
Improper Authentication
Low WAF Coverage
OWASP: A07:2021 Identification and Authentication Failures
Affected Software
| Vendor | Product | Version |
|---|---|---|
| qnap | qvr | 5.1.0 - 5.1.6 |
| qnap | qvr | 5.1.6 |
References
- www.qnap.com (Vendor Advisory)