LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-47565: QNAP VioStor NVR OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 21, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 11, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-47565 to its Known Exploited Vulnerabilities catalog on Dec 21, 2023, with a federal patch deadline of Jan 11, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

CVE-2023-47565 is an OS command injection vulnerability in QNAP VioStor NVR devices. It allows authenticated users to execute operating system commands over the network. Network video recorders of this type commonly sit on internal networks and store or stream surveillance footage, so successful abuse can give an attacker a foothold for further movement, data access, or device takeover. Confirm all product and version details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-78, OS command injection. In products of this class, user-supplied input that reaches a shell or system call is not properly sanitized. An authenticated attacker who can reach the vulnerable interface over the network can craft input that the device interprets as additional operating-system commands. Those commands then run with the privileges of the process that handles the request. Public detail on exact injection points or required parameters is limited; treat any network-accessible authenticated function on the NVR as potentially in scope until the vendor advisory is reviewed.

Am I affected? How to find it in your systems

QNAP VioStor NVR appliances are purpose-built network video recorders typically deployed for CCTV and surveillance workloads. They appear on local networks, sometimes with management interfaces exposed to wider segments or the internet. Inventory steps include:

Telemetry that may indicate exploitation includes unexpected process launches, shell history entries, or outbound connections originating from the NVR after an authenticated session. Because the vulnerability requires authentication, also examine authentication logs for unusual accounts or source IPs. Specific log signatures are not provided in public summaries; rely on vendor guidance and baseline the device’s normal behavior.

How to remediate

The primary action is to apply the mitigations or updates published by QNAP for this vulnerability. Follow the vendor instructions exactly; if no fix is available, CISA directs organizations to discontinue use of the product. After patching:

Document the change and re-scan the device to ensure the vulnerable condition is no longer present.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps lower risk but do not eliminate the vulnerability; schedule the official remediation as soon as possible. If mitigations cannot be applied, plan to remove the device from service.

If your data may have been exposed

Command-injection flaws on network-attached devices can lead to full system compromise and subsequent data access or lateral movement. Known ransomware use of this specific CVE is not documented, yet any successful exploitation still warrants investigation of the device and connected systems for unauthorized activity. Review video storage, configuration backups, and any credentials stored on or used by the NVR. Organizations that suspect exposure can also run a free exposure scan of their email addresses against known breach data sets to identify whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQNAP · VioStor NVR
WeaknessCWE-78
Added to CISA KEVDec 21, 2023
Federal patch deadlineJan 11, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities