ZeroHour

CVE-2018-19953

KEV ransomwaremass

Cross-Site Scripting in QNAP NAS File Station

CISA: QNAP NAS File Station Cross-Site Scripting Vulnerability

CVSS 3.1
6.1 medium
EPSS
24%p98
Published
()
KEV added
AI analysis

CVE-2018-19953 is a cross-site scripting (XSS) flaw in File Station, the web-based file management application bundled with QNAP network-attached storage (NAS) devices. A remote attacker can inject malicious code through the application, which then executes in the browser of users who access the File Station interface. Successful injection can let the attacker run scripts in an authenticated user's session, potentially stealing credentials or performing actions on the NAS with that user's privileges. Any organization or individual running File Station on a QNAP NAS is affected; the specific vulnerable version ranges are not provided in the available data and should be confirmed against QNAP's advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-24 with a known ransomware association, indicating active in-the-wild exploitation, though no public proof-of-concept code is known.

What to do: Apply QNAP's security updates per vendor instructions, as required by CISA's KEV listing, and confirm the affected QTS/File Station versions in QNAP's advisory before scheduling the update. Until patched, restrict File Station's internet exposure via firewall rules, access controls, or VPN-only access, and review NAS logs for signs of intrusion given the known ransomware association.

Affected
QNAP Network Attached Storage (NAS) - File Station
Estimated exposure
mass>1M+ QNAP NAS installations (File Station is bundled across QNAP's NAS line; exact vulnerable version range unspecified) — QNAP is a leading NAS vendor with a multi-million-unit install base and File Station shipped as its standard web file manager, while public internet scans have indexed hundreds of thousands of QNAP devices over time, so the plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CISA Known Exploited Vulnerability
Affected
QNAP Network Attached Storage (NAS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
qts
Weakness
CWE-79, CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.