Home

Description

An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621 and later

PUBLISHED Reserved 2025-06-20 | Published 2025-08-29 | Updated 2025-08-30 | Assigner qnap




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-287

Product status

Default status
unaffected

5.1.0 before 5.1.6 build 20250621
affected

Credits

360 的安全研究员 侯留洋(houliuyang@360.cn) finder

References

www.qnap.com/en/security-advisory/qsa-25-29

cve.org (CVE-2025-52856)

nvd.nist.gov (CVE-2025-52856)

Download JSON