CVE-2019-7201: QNAP Netbak Replicator
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges. QNAP have already fixed this issue in QNAP NetBak Replicator 4.5.12.1108.
Affected products
- QNAP Netbak Replicator: up to and including 4.5.11.816
Published 2019-12-04. Last modified 2026-06-17.