CVE-2019-7193criticalunder attackransomwareCWE-20

CVE-2019-7193: critical vulnerability in QNAP NAS devices

Published · Updated

83Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 14%
from disclosure to weapon
Published on NVDDec 5
CISA KEV+916d
exploitation probability
14%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-06-22

Apply updates per vendor instructions.

In short

A QNAP NAS system fails to properly validate user input, allowing remote attackers to inject and execute arbitrary code without needing to be logged in. This is a critical flaw because it gives attackers complete control over the device.

Technical detail

CWE-20 improper input validation vulnerability in QNAP QTS enables remote code injection via unvalidated input parameters. The attack vector is network-based with no authentication requirement; exploitation allows arbitrary code execution with system privileges. QNAP mitigation requires updating to patched QTS versions.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · QNAP NAS devices
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.