CVE-2018-19953
KEV ransomwaremassCross-Site Scripting in QNAP NAS File Station
CISA: QNAP NAS File Station Cross-Site Scripting Vulnerability
CVE-2018-19953 is a cross-site scripting (XSS) flaw in File Station, the web-based file management application bundled with QNAP network-attached storage (NAS) devices. A remote attacker can inject malicious code through the application, which then executes in the browser of users who access the File Station interface. Successful injection can let the attacker run scripts in an authenticated user's session, potentially stealing credentials or performing actions on the NAS with that user's privileges. Any organization or individual running File Station on a QNAP NAS is affected; the specific vulnerable version ranges are not provided in the available data and should be confirmed against QNAP's advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-24 with a known ransomware association, indicating active in-the-wild exploitation, though no public proof-of-concept code is known.
What to do: Apply QNAP's security updates per vendor instructions, as required by CISA's KEV listing, and confirm the affected QTS/File Station versions in QNAP's advisory before scheduling the update. Until patched, restrict File Station's internet exposure via firewall rules, access controls, or VPN-only access, and review NAS logs for signs of intrusion given the known ransomware association.
| QNAP Network Attached Storage (NAS) - File Station | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
- Affected
- QNAP Network Attached Storage (NAS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- qts
- Weakness
- CWE-79, CWE-80
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.