← Vulnerability feed

Vulnerability record · CVE-2019-7193 · published 5 December 2019

CVE-2019-7193: QNAP QTS improper input validation allows remote code injection

Qnap · Qts

QNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable without authentication and has been exploited in ransomware campaigns, so unpatched NAS devices are at serious risk.

9.8 CVSS 3.1 Critical CISA KEV since 8 Jun 2022 Known ransomware use EPSS 14% · top 3.5% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, active KEV listing, documented ransomware use, and public exploit code make this an urgent patch target.

What it is

QNAP QTS contains an improper input validation flaw that lets remote attackers inject arbitrary code into the system. It is remotely reachable without authentication and has been exploited in ransomware campaigns, so unpatched NAS devices are at serious risk.

Impact

An attacker can execute arbitrary code on the affected QTS system, gaining full control of the NAS and any data or services it hosts.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N), so any exposed QTS interface is a potential entry point.

Exploitation

CVE-2019-7193 is listed in CISA KEV with known ransomware campaign use, and public exploit code exists per Packet Storm references; EPSS 30-day probability is about 14.4 percent (96th percentile).

What to do

  • Update QTS to the latest vendor-recommended version per the QNAP security advisory NAS-201911-25.
  • Remove or restrict internet exposure of QTS management interfaces; place NAS administration behind VPN or trusted networks.
  • Apply network segmentation and firewall rules so NAS devices cannot be reached directly from untrusted networks.
  • Monitor for and block known exploitation and ransomware indicators targeting QNAP devices.
  • Verify patching status across all QNAP NAS assets, including any that were offline during prior update cycles.

Detection

  • Review QTS and web server logs for unusual POST requests or command-injection patterns against management endpoints.
  • Alert on unexpected child processes spawned by QTS web services (for example shell or scripting interpreters).
  • Monitor for new or modified files in QTS web directories and unexpected outbound connections from NAS devices.
  • Correlate NAS host telemetry with ransomware indicators and known QNAP exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-7193 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "QNAP QTS Improper Input Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7193 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2509QNAP QTS and QuTS hero command injectionQTS and QuTS hero contain a command injection flaw that lets an attacker run arbitrary commands within a compromised application. It is remotely reac…KEVEPSS 34%analysed9.8CVE-2018-19949QNAP QTS File Station command injection allows remote code executionQNAP QTS contains a command injection flaw in File Station that lets remote attackers run arbitrary commands on the NAS. It is remotely reachable wit…KEVEPSS 28%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed6.1CVE-2018-19953QNAP QTS File Station cross-site scripting flawQNAP QTS contains a cross-site scripting vulnerability in File Station that lets remote attackers inject malicious code. It matters because the flaw …KEVEPSS 29%analysed5.4CVE-2018-19943QNAP QTS File Station cross-site scriptingQNAP QTS contains a cross-site scripting flaw in File Station that lets a remote attacker inject malicious code. It matters because the vendor has fi…KEVEPSS 21%analysed10.0CVE-2024-32766Qnap qts command injection vulnerabilityAn OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…EPSS 2.3%10.0CVE-2017-7876Qnap qts command injection vulnerabilityThis command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the is…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2019-7193), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.