TROYANOSYVIRUS
Back to CVEs

CVE-2018-19949

CRITICALCISA KEV
9.8

Description

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/28/2020
Last Modified11/3/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorQNAP
ProductNetwork Attached Storage (NAS)
Vulnerability NameQNAP NAS File Station Command Injection Vulnerability
KEV Date Added2022-05-24
Remediation Due Date2022-06-14
Ransomware UseKnown

Affected Products

qnap:qts

Weaknesses (CWE)

CWE-20CWE-77CWE-78CWE-77

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.