QNAP Surveillance Station
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in QNAP Surveillance Station.
By the Year
In 2026 there have been 1 vulnerability in QNAP Surveillance Station with an average score of 7.8 out of ten. Last year, in 2025 Surveillance Station had 2 security vulnerabilities published. Right now, Surveillance Station is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 7.80 |
| 2025 | 2 | 0.00 |
It may take a day or so for new Surveillance Station vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent QNAP Surveillance Station Security Vulnerabilities
Argus DVR 4.0 Unquoted Service Path Local Priv Esc
CVE-2021-47945
7.8 - High
- May 10, 2026
Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.
Unquoted Search Path or Element
Astak CM-818T3 Unauth Config Disclosure via backup.cgi
CVE-2020-36873
- November 26, 2025
Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed configuration backup without requiring authentication or authorization. The exposed backup may include administrative credentials and other sensitive device settings, enabling an unauthenticated remote attacker to obtain information that could facilitate further compromise of the camera or connected network.
Missing Authentication for Critical Function
Cyclope Employee Surveillance RCE via SQL Injection
CVE-2012-10047
- August 08, 2025
Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL statements. This can be leveraged to write and execute a malicious PHP file on disk, resulting in remote code execution under the SYSTEM user context.
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for QNAP Surveillance Station or by QNAP? Click the Watch button to subscribe.