QNAP NAS 未授权任意文件读取、未授权... CVE-2019-7192~7195

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# QNAP Pre-Auth Root RCE Affecting ~450K Devices on the Internet In 2019, I discovered multiple vulnerabilities in QNAP PhotoStation and CGI programs. These vulnerabilities can be chained into a **pre-auth root RCE**. All QNAP NAS models are vulnerable, and there are ~450K vulnerable QNAS NAS instances on the Internet (statistical prediction). These vulnerabilities have been responsibly reported, fixed and assigned [CVE-2019-7192](https://nvd.nist.gov/vuln/detail/CVE-2019-7192\)) (CVSS 9.8), [CVE-2019-7193](https://nvd.nist.gov/vuln/detail/CVE-2019-71923) (CVSS 9.8), [CVE-2019-7194](https://nvd.nist.gov/vuln/detail/CVE-2019-7194) (CVSS 9.8), [CVE-2019-7195](https://nvd.nist.gov/vuln/detail/CVE-2019-7195) (CVSS 9.8). This article is the first public disclosure, but only 3 of the vulnerabilities are disclosed, because they're enough to achieve pre-auth root RCE. # Impact ## Vulnerable Instances The following Shodan search reveals 564K QNAP instances on the Internet. Among those, 8 of...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息