QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.