CVE-2018-19949

CRITICAL(9.8)KEVRansomwareElevated Risk

QNAP NAS File Station Command Injection Vulnerability

Description

CVE-2018-19949 is a command injection vulnerability in QNAP NAS File Station that allows remote attackers to execute arbitrary operating system commands on the affected network-attached storage device. By sending crafted requests to the File Station web interface, an attacker can inject and execute system-level commands, potentially gaining complete control over the NAS device and all data stored on it. CISA has confirmed active exploitation and flagged CVE-2018-19949 as associated with ransomware campaigns targeting NAS devices. With an EPSS percentile of 97.5%, this vulnerability is among the most likely to be actively exploited.

KEV Information

Vendor
QNAP
Product
Network Attached Storage (NAS)
Date Added
May 24, 2022
Due Date
June 14, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
qnapqts< 4.2.6; >= 4.3.1.0013, < 4.3.3.1161; >= 4.3.4, < 4.3.4.1190; >= 4.3.6, < 4.3.6.1218; >= 4.4.0, < 4.4.1.1201; >= 4.4.2, < 4.4.2.1231; 4.2.6

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Since no specific CWE has been assigned to CVE-2018-19949, the underlying weakness type remains formally unspecified. However, the vulnerability is a command injection flaw where the File Station application fails to properly sanitize user input before passing it to operating system command execution functions. This allows an attacker to append or inject arbitrary commands that are executed by the underlying operating system with the privileges of the File Station process.

Impact Analysis

CVE-2018-19949 allows remote attackers to execute arbitrary commands on QNAP NAS devices through the File Station web interface, providing full control over the storage device. The impact is severe: an attacker can read, modify, encrypt, or delete all files stored on the NAS, install persistent backdoors or malware, access network credentials and configuration data stored on the device, and use the compromised NAS as a pivot point for lateral movement within the network. QNAP NAS devices frequently serve as primary data storage for homes and businesses, containing critical documents, database backups, and media files. CISA's ransomware association confirms that this command injection vulnerability has been used in ransomware campaigns that encrypt NAS data and demand payment for recovery. The EPSS percentile of 97.5% reflects the high frequency of exploitation targeting internet-exposed NAS devices.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2018-19949 by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 14, 2022. CISA has flagged this vulnerability as associated with ransomware campaigns, confirming its use in ransomware attacks that target NAS devices to encrypt stored data. The EPSS percentile of 97.5% confirms high exploitation likelihood. Command injection vulnerabilities in NAS devices are particularly dangerous because they provide direct operating system access, and QNAP NAS devices have been among the most frequently targeted storage platforms by ransomware operators, with multiple ransomware families specifically designed to exploit QNAP vulnerabilities.

Remediation

  1. Apply firmware updates from QNAP that address CVE-2018-19949 immediately. CISA's required action is to apply updates per vendor instructions.
  2. Disconnect the NAS device from the internet by disabling UPnP auto-port-forwarding and removing any manual port forwarding rules that expose the NAS web interface externally.
  3. If remote access is required, configure it only through a VPN connection rather than direct internet exposure of the NAS management interface.
  4. Review the NAS for signs of compromise, including unexpected files, processes, or user accounts that may have been created through command injection exploitation.
  5. Enable and review NAS system logs for suspicious command execution activity, and implement network monitoring to detect anomalous traffic to and from the NAS device.

Technical Details

CVE-2018-19949 is a command injection vulnerability in the File Station component of QNAP NAS devices. File Station provides a web-based interface for managing files stored on the NAS. The vulnerability exists because the File Station application incorporates user-supplied input into operating system commands without proper sanitization or parameterization. An attacker can craft HTTP requests to the File Station interface that include shell metacharacters (such as semicolons, pipes, backticks, or command substitution syntax) in parameters that are subsequently passed to system command execution functions. When the NAS processes these requests, the injected commands are executed by the underlying Linux operating system with the privileges of the web application process, which on QNAP devices typically runs with elevated permissions. This provides the attacker with direct shell access to the NAS device, enabling arbitrary file operations, process management, and network access from the compromised device.

Frequently Asked Questions

Is CVE-2018-19949 being actively exploited?

Yes, CISA has confirmed active exploitation of CVE-2018-19949 and has flagged it as associated with ransomware campaigns. The EPSS percentile of 97.5% confirms high exploitation probability. QNAP NAS devices have been frequent targets for ransomware operations that encrypt stored data.

What products are affected by CVE-2018-19949?

CVE-2018-19949 affects QNAP Network Attached Storage (NAS) devices, specifically the File Station component. All QNAP NAS models running firmware versions that contain this command injection vulnerability are affected until updated.

How do I fix CVE-2018-19949?

Apply the latest firmware updates from QNAP immediately. Remove the NAS from direct internet exposure by disabling port forwarding and UPnP. If remote access is needed, use a VPN rather than exposing the NAS web interface directly.

How severe is CVE-2018-19949?

CVE-2018-19949 is a command injection vulnerability with an EPSS percentile of 97.5% and a confirmed ransomware association. It allows remote attackers to execute arbitrary operating system commands on QNAP NAS devices, providing full control over the device and all stored data. This makes it one of the most critical vulnerabilities affecting NAS environments.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score24.45%
EPSS Percentile97.7%

Dates

PublishedOctober 28, 2020
Last ModifiedAugust 13, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.