EXPOSURES › CVE-2019-7193
CVE-2019-7193
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQNAP QTS suffered an improper input validation flaw allowing remote code execution, which was actively exploited in the wild and linked to ransomware attacks.
QNAP's QTS platform had an improper input validation vulnerability enabling remote attackers to inject code, a critical flaw that was actively exploited in the wild and linked to ransomware. DIB organizations must ensure all QNAP systems are patched immediately and monitor for similar unpatched vulnerabilities in their supply chain. This failure highlights the severe risks of relying on unpatched hardware and software, especially when flaws are exploited in the wild.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a severe, avoidable failure with significant reputational and security impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.