Junglewise Threat Intelligence

CVE-2018-19949: QNAP NAS File Station Command Injection Vulnerability

CVE-2018-19949 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-24

Technologies: QNAP Network Attached Storage (NAS). Vendors: QNAP.

Executive brief

A command injection vulnerability in QNAP NAS File Station allows remote attackers to execute arbitrary commands on the affected system. The vulnerability stems from improper neutralization of special elements used in a command.

Affected products

  • QNAP QTS (File Station) < 4.4.2.1231 build 20200302
  • QNAP QTS (File Station) < 4.4.1.1201 build 20200130
  • QNAP QTS (File Station) < 4.3.6.1218 build 20200214
  • QNAP QTS (File Station) < 4.3.4.1190 build 20200107
  • QNAP QTS (File Station) < 4.3.3.1161 build 20200109
  • QNAP QTS (File Station) < 4.2.6 build 20200109

Timeline

  • 2020-10-28: disclosed: NVD Published Date
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats