CVE-2018-19949
KEV ransomwaremassRemote Command Injection in QNAP NAS File Station
CISA: QNAP NAS File Station Command Injection Vulnerability
CVE-2018-19949 is a command injection flaw (CWE-77/CWE-78, with CWE-20 input-validation weakness) in File Station, the web-based file management application on QNAP network-attached storage (NAS) devices. By sending crafted requests to the File Station service, a remote attacker can cause the NAS to execute arbitrary operating system commands. Successful exploitation yields command execution on the device, which attackers can use to install malware or ransomware, access or destroy data stored on the NAS, and pivot deeper into the victim network. Any QNAP NAS running the File Station component is potentially affected; the source data does not specify an exact affected version range, so defenders should consult QNAP's advisory. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24) with known ransomware use, confirming active exploitation in the wild, and EPSS rates near-term exploitation risk at about 24% (98th percentile).
What to do: Apply the latest QNAP firmware/QTS updates per the vendor's instructions, as required by CISA's KEV listing. Restrict internet exposure of the NAS web interface and File Station (e.g., firewall rules or VPN-only access instead of port forwarding) to reduce attack surface. Check NAS and network logs for signs of unexpected command execution or ransomware activity, given the known ransomware abuse of this flaw.
| QNAP Network Attached Storage (NAS) - File Station | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
- Affected
- QNAP Network Attached Storage (NAS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- qts
- Weakness
- CWE-20, CWE-77, CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.