CVE-2019-7193: critical vulnerability in QNAP NAS devices
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A QNAP NAS system fails to properly validate user input, allowing remote attackers to inject and execute arbitrary code without needing to be logged in. This is a critical flaw because it gives attackers complete control over the device.
CWE-20 improper input validation vulnerability in QNAP QTS enables remote code injection via unvalidated input parameters. The attack vector is network-based with no authentication requirement; exploitation allows arbitrary code execution with system privileges. QNAP mitigation requires updating to patched QTS versions.
The full analysis of this CVE is available in Portuguese →