Vulnerability record · CVE-2019-7193 · published 5 December 2019
CVE-2019-7193: QNAP QTS improper input validation allows remote code injection
Qnap · Qts
QNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable without authentication and has been exploited in ransomware campaigns, so unpatched NAS devices are at serious risk.
Description
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, active KEV listing, documented ransomware use, and public exploit code make this an urgent patch target.
What it is
QNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable without authentication and has been exploited in ransomware campaigns, so unpatched NAS devices are at serious risk.
Impact
An attacker can execute arbitrary code on the affected QTS system, gaining full control of the NAS and any data or services it hosts.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N), so any exposed QTS interface is a potential entry point.
Exploitation
CVE-2019-7193 is listed in CISA KEV with known ransomware campaign use, and public exploit code exists per Packet Storm references; EPSS 30-day probability is about 14.4 percent (96th percentile).
What to do
- Update QTS to the latest vendor-recommended version per the QNAP security advisory NAS-201911-25.
- Remove or restrict internet exposure of QTS management interfaces; place NAS administration behind VPN or trusted networks.
- Apply network segmentation and firewall rules so NAS devices cannot be reached directly from untrusted networks.
- Monitor for and block known exploitation and ransomware indicators targeting QNAP devices.
- Verify patching status across all QNAP NAS assets, including any that were offline during prior update cycles.
Detection
- Review QTS and web server logs for unusual POST requests or command-injection patterns against management endpoints.
- Alert on unexpected child processes spawned by QTS web services (for example shell or scripting interpreters).
- Monitor for new or modified files in QTS web directories and unexpected outbound connections from NAS devices.
- Correlate NAS host telemetry with ransomware indicators and known QNAP exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7193 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "QNAP QTS Improper Input Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 | Vendor Advisory |
| http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7193 | US Government Resource |
Track CVE-2019-7193 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7193), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.