CVE-2019-7193

CRITICAL(9.8)KEVRansomwareElevated Risk

QNAP QTS Improper Input Validation Vulnerability

Description

CVE-2019-7193 is an improper input validation vulnerability in QNAP QTS, the operating system powering QNAP NAS devices. The flaw allows remote attackers to inject malicious code on the system by exploiting insufficient validation of user-supplied input. Successful exploitation can lead to arbitrary code execution, giving attackers full control over the QNAP NAS device and all data stored on it. CISA has added CVE-2019-7193 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 25.8% (96th percentile), this QNAP QTS vulnerability represents a high-priority threat requiring immediate patching.

KEV Information

Vendor
QNAP
Product
QTS
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
qnapqts4.3.6.0895; 4.3.6.0907; 4.3.6.0923; 4.3.6.0944; 4.3.6.0959; 4.3.6.0979; 4.3.6.0993; 4.3.6.1013; 4.3.6.1033; 4.4.1.0948; 4.4.1.0949; 4.4.1.0978; 4.4.1.0998; 4.4.1.0999; 4.4.1.1031; 4.4.1.1033

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-20: Improper Input Validation

CVE-2019-7193 exploits an improper input validation weakness in QNAP QTS, where the operating system fails to adequately validate user-supplied data before processing it. This allows remote attackers to provide malicious input that is interpreted as executable code, bypassing intended security boundaries and achieving code injection on the NAS device.

Learn more: CWE-20 — Improper Input Validation

Impact Analysis

CVE-2019-7193 is a severe vulnerability in QNAP QTS that allows remote attackers to inject and execute code on the NAS device through improper input validation. The vulnerability is remotely exploitable, meaning any attacker with network access to the QNAP device can attempt exploitation. Confidentiality is critically impacted as code execution enables access to all data stored on the NAS, including files, credentials, and network configurations. Integrity and availability are equally at risk, as an attacker can modify or delete data, alter system configurations, and deploy ransomware. The EPSS score of 25.8% (96th percentile) indicates high exploitation probability, and CISA has confirmed ransomware usage associated with this vulnerability. As part of the QNAP vulnerability cluster (CVE-2019-7192 through CVE-2019-7195), this flaw contributes to a comprehensive attack surface that ransomware operators have actively exploited.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2019-7193 with known ransomware usage documented. The EPSS score of 25.8% (96th percentile) reflects high exploitation probability. This vulnerability is part of the broader QNAP vulnerability cluster that includes CVE-2019-7192, CVE-2019-7194, and CVE-2019-7195, which are frequently exploited together by ransomware operators targeting internet-exposed QNAP NAS devices. The combination of an input validation flaw in the QTS operating system with path traversal and access control weaknesses in Photo Station creates a devastating multi-stage attack that has been successfully deployed by ransomware families targeting QNAP infrastructure.

Remediation

  1. Update QNAP QTS immediately to the latest patched version as required by the CISA KEV catalog. Check the QNAP Security Advisory for specific version information addressing CVE-2019-7193.
  2. Remove the QNAP NAS from direct internet exposure by disabling UPnP automatic port forwarding, removing manual port forwarding rules from your router, and disabling the myQNAPcloud remote access service.
  3. Implement strict input validation for any custom applications or scripts running on the QNAP QTS platform, and review QNAP App Center applications for potential exposure.
  4. Enable QNAP Security Counselor to audit the security posture of the NAS and identify additional configuration weaknesses that could be exploited in conjunction with this vulnerability.
  5. Maintain verified offline backups of all critical NAS data, and test backup restoration procedures regularly to ensure recovery capability in the event of a ransomware attack targeting this vulnerability.

Technical Details

CVE-2019-7193 is an improper input validation vulnerability in QNAP QTS, the Linux-based operating system running on QNAP NAS devices. The vulnerability exists because QTS does not adequately validate and sanitize user-supplied input before it is processed by system components, allowing an attacker to inject malicious code that is subsequently executed by the operating system. The improper input validation can be triggered remotely through network-accessible interfaces, where the injected code runs with the privileges of the vulnerable QTS service. Given that QTS services typically run with elevated privileges to manage storage, networking, and device configuration, successful exploitation provides an attacker with significant control over the device. This vulnerability complements the path traversal flaws in Photo Station (CVE-2019-7194, CVE-2019-7195) and the access control weakness (CVE-2019-7192), providing attackers with multiple entry points into the QNAP device.

Frequently Asked Questions

Is CVE-2019-7193 being actively exploited?

Yes. CISA has confirmed active exploitation with known ransomware usage. The EPSS score of 25.8% (96th percentile) indicates high exploitation probability. Ransomware operators have targeted QNAP NAS devices through this vulnerability as part of a broader attack chain.

What products are affected by CVE-2019-7193?

CVE-2019-7193 affects QNAP QTS, the operating system running on QNAP NAS devices. All QTS versions prior to the security fix are vulnerable. This impacts the entire range of QNAP NAS devices regardless of hardware model.

How do I fix CVE-2019-7193?

Update QNAP QTS to the latest patched version as specified in the QNAP Security Advisory. Remove the NAS from direct internet exposure, implement VPN-based remote access, and maintain offline backups to mitigate ransomware risk.

How severe is CVE-2019-7193?

CVE-2019-7193 is a high-severity code injection vulnerability with an EPSS score of 25.8% in the 96th percentile and confirmed ransomware exploitation. The vulnerability enables remote code execution on the QNAP NAS, potentially compromising all stored data and device functionality.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score14.37%
EPSS Percentile96.3%

Dates

PublishedDecember 5, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.