CVE-2019-7193 is a critical improper input validation vulnerability affecting QNAP QTS, allowing remote attackers to inject arbitrary code. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited, notably in known ransomware campaigns, and has garnered significant community discussion and media coverage, despite a lack of public exploit code in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3.6.0895CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.6.0895:-:*:*:*:*:*:* | ||
4.3.6.0907CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.6.0907:-:*:*:*:*:*:* | ||
4.3.6.0923CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.6.0923:-:*:*:*:*:*:* | ||
4.3.6.0944CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.6.0944:-:*:*:*:*:*:* | ||
4.3.6.0959CPE matchmatch criteria | cpe:2.3:o:qnap:qts:4.3.6.0959:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.