Description

QNAP Systems has released critical updates for older VioStor NVR devices running QVR 5.1.x firmware to address two newly discovered security vulnerabilities, reported on August 29, 2025. These flaws could potentially allow unauthorized access to video surveillance systems. The first issue, identified as CVE?2025?52856, involves weak authentication mechanisms. This could enable attackers to access devices without valid credentials, risking exposure of surveillance footage and unauthorized system control. The second vulnerability, CVE?2025?52861, is a path traversal flaw that can be exploited after gaining administrative privileges. It allows access to sensitive system files beyond intended limits, further compounding potential damage. Both vulnerabilities carry an “Important” severity rating and were reported by Hou Liuyang of 360 Security. QNAP responded by releasing QVR firmware version 5.1.6 build 20250621 (or newer), which addresses both issues. Users of affected VioStor NVR devices are advised to check their firmware version via Control Panel > System Settings > Firmware Update. The latest firmware can be downloaded from the QNAP Download Center and installed manually. QNAP also stresses the importance of regularly applying updates and monitoring device support status to ensure continued security.