QNAP known exploited vulnerabilities
CISA lists 11 QNAP CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2023-12-21), and 9 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2019-7195 (Photo Station): EPSS 89.7%, added 2022-06-08
- CVE-2019-7192 (Photo Station): EPSS 88.1%, added 2022-06-08
- CVE-2022-27593 (Photo Station): EPSS 87.9%, added 2022-09-08
- CVE-2019-7194 (Photo Station): EPSS 83.1%, added 2022-06-08
- CVE-2021-28799 (Network Attached Storage (NAS)): EPSS 78.2%, added 2022-03-31
Most affected QNAP products
Photo Station (4), Network Attached Storage (NAS) (4), VioStor NVR (1), QTS (1), QNAP Network-Attached Storage (NAS) (1).
All QNAP CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2023-47565 | VioStor NVR | VioStor NVR OS Command Injection | 2023-12-21 | 2024-01-11 | 73.3% | – |
| CVE-2022-27593 | Photo Station | Photo Station Externally Controlled Reference | 2022-09-08 | 2022-09-29 | 87.9% | Yes |
| CVE-2019-7195 | Photo Station | Photo Station Path Traversal | 2022-06-08 | 2022-06-22 | 89.7% | Yes |
| CVE-2019-7194 | Photo Station | Photo Station Path Traversal | 2022-06-08 | 2022-06-22 | 83.1% | Yes |
| CVE-2019-7193 | QTS | QTS Improper Input Validation | 2022-06-08 | 2022-06-22 | 14.4% | Yes |
| CVE-2019-7192 | Photo Station | Photo Station Improper Access Control | 2022-06-08 | 2022-06-22 | 88.1% | Yes |
| CVE-2018-19953 | Network Attached Storage (NAS) | NAS File Station Cross-Site Scripting | 2022-05-24 | 2022-06-14 | 28.8% | Yes |
| CVE-2018-19949 | Network Attached Storage (NAS) | NAS File Station Command Injection | 2022-05-24 | 2022-06-14 | 28.4% | Yes |
| CVE-2018-19943 | Network Attached Storage (NAS) | NAS File Station Cross-Site Scripting | 2022-05-24 | 2022-06-14 | 21.5% | Yes |
| CVE-2020-2509 | QNAP Network-Attached Storage (NAS) | Network-Attached Storage (NAS) Command Injection | 2022-04-11 | 2022-05-02 | 34.0% | – |
| CVE-2021-28799 | Network Attached Storage (NAS) | NAS Improper Authorization | 2022-03-31 | 2022-04-21 | 78.2% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors