CVE-2019-7193: QNAP QTS Improper Input Validation Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 14.4% chance of exploitation in the next 30 days.

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

Affected products

  • QNAP QTS: version 4.3.6.0895 only; version 4.3.6.0907 only; version 4.3.6.0923 only; version 4.3.6.0944 only; version 4.3.6.0959 only; version 4.3.6.0979 only; …

Published 2019-12-05. Last modified 2026-06-17.