CVE-2019-7193
KEV ransomware PoC massUnauthenticated Remote Code Execution in QNAP QTS via Improper Input Validation
CISA: QNAP QTS Improper Input Validation Vulnerability
CVE-2019-7193 is an improper input validation flaw (CWE-20) in QNAP's QTS NAS operating system, affecting its network-facing Photo Station web application, that allows remote, unauthenticated attackers to inject arbitrary code into the system. It is triggered by crafted requests sent to the Photo Station/QTS web interface, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that exploitation requires no credentials, privileges, or user interaction; a public proof-of-concept demonstrates remote command execution against QTS running Photo Station 6.0.3. A successful attacker gains the ability to execute arbitrary code on the NAS, which typically means full control of the device and its stored data, creating a stepping stone for data theft and ransomware deployment. Any organization or individual running QNAP QTS with the Photo Station component enabled is affected, especially devices whose web interface is exposed to the internet. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and its EPSS score of 14.4% (96th percentile) indicates an elevated near-term probability of exploitation.
What to do: Update QTS to the latest version available for your model per QNAP's instructions, as the vendor states updating to current QTS releases fixes the vulnerability; if patching is delayed, restrict or disable internet exposure of Photo Station and the QTS web UI. Review NAS devices for signs of compromise such as unknown processes, unexpected scheduled jobs, modified files, or ransomware artifacts, since known exploitation includes ransomware campaigns and internet-exposed QNAP NAS are frequent targets of both criminal and state-linked actors.
| QNAP QTS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.
- Affected
- QNAP QTS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- qts
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H