ZeroHour

CVE-2018-19949

KEV ransomwaremass

Remote Command Injection in QNAP NAS File Station

CISA: QNAP NAS File Station Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
24%p98
Published
()
KEV added
AI analysis

CVE-2018-19949 is a command injection flaw (CWE-77/CWE-78, with CWE-20 input-validation weakness) in File Station, the web-based file management application on QNAP network-attached storage (NAS) devices. By sending crafted requests to the File Station service, a remote attacker can cause the NAS to execute arbitrary operating system commands. Successful exploitation yields command execution on the device, which attackers can use to install malware or ransomware, access or destroy data stored on the NAS, and pivot deeper into the victim network. Any QNAP NAS running the File Station component is potentially affected; the source data does not specify an exact affected version range, so defenders should consult QNAP's advisory. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24) with known ransomware use, confirming active exploitation in the wild, and EPSS rates near-term exploitation risk at about 24% (98th percentile).

What to do: Apply the latest QNAP firmware/QTS updates per the vendor's instructions, as required by CISA's KEV listing. Restrict internet exposure of the NAS web interface and File Station (e.g., firewall rules or VPN-only access instead of port forwarding) to reduce attack surface. Check NAS and network logs for signs of unexpected command execution or ransomware activity, given the known ransomware abuse of this flaw.

Affected
QNAP Network Attached Storage (NAS) - File Station
Estimated exposure
mass≈ hundreds of thousands of internet-exposed QNAP NAS devices out of a multi-million-unit installed base — QNAP has shipped millions of NAS units and public internet scans routinely index on the order of hundreds of thousands of exposed QNAP NAS web interfaces, though only deployments with File Station reachable by remote attackers are directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CISA Known Exploited Vulnerability
Affected
QNAP Network Attached Storage (NAS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
qts
Weakness
CWE-20, CWE-77, CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.