Qvis develops digital video recording and network video recording appliances for surveillance deployments, with its vulnerability footprint concentrating in the firmware that underpins these devices. The recurring weakness pattern centers on deserialization of untrusted data, a structural risk in devices that accept remote configuration and firmware updates. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qvis over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41419CRITICAL QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. | Jul 18, 2022 | 9.8 | 46 | NO | YES |
CVE-2021-44954HIGH In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration. | Jul 18, 2022 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qvis.
Media articles that mention a CVE ID that affects a product developed by Qvis — matched by CVE ID, not by vendor name.