CVE-2018-19953

MEDIUM(6.1)KEVRansomwareElevated Risk

QNAP NAS File Station Cross-Site Scripting Vulnerability

Description

CVE-2018-19953 is a cross-site scripting (XSS) vulnerability in QNAP NAS File Station that allows remote attackers to inject malicious code into the web interface. By exploiting this flaw, an attacker can execute arbitrary JavaScript in the context of an authenticated user's browser session, potentially stealing session cookies, credentials, and sensitive data stored on the NAS device. CISA has confirmed active exploitation and flagged CVE-2018-19953 as associated with ransomware campaigns, indicating it has been leveraged in ransomware operations targeting network-attached storage devices. With an EPSS percentile of 96.7%, this vulnerability is among the most likely to be exploited.

KEV Information

Vendor
QNAP
Product
Network Attached Storage (NAS)
Date Added
May 24, 2022
Due Date
June 14, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7

CWEs

Affected Products

VendorProductVersion
qnapqts< 4.2.6; >= 4.3.1.0013, < 4.3.3.1161; >= 4.3.4, < 4.3.4.1190; >= 4.3.6, < 4.3.6.1218; >= 4.4.0, < 4.4.1.1201; >= 4.4.2, < 4.4.2.1231; 4.2.6

Multiple CVSS Assessments

Source: [email protected](Primary)
6.1
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
6.1
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

Weakness Type

Since no specific CWE has been assigned to CVE-2018-19953, the underlying weakness type remains formally unspecified. However, the vulnerability is a cross-site scripting (XSS) flaw in the QNAP NAS File Station web interface. XSS vulnerabilities occur when an application includes untrusted data in web page output without proper sanitization or encoding, allowing an attacker to inject and execute malicious scripts in the context of another user's browser session.

Impact Analysis

CVE-2018-19953 enables cross-site scripting attacks against users of the QNAP NAS File Station web interface. An attacker can inject malicious JavaScript that executes in the victim's browser with the privileges of their authenticated session. This can lead to theft of session cookies and authentication tokens, unauthorized access to files and data stored on the NAS, modification or deletion of files through the victim's session, and redirection of the user to phishing pages for credential harvesting. QNAP NAS devices are commonly used for data storage in both home and business environments, and often contain sensitive documents, backups, and media files. CISA's ransomware association confirms that this XSS vulnerability has been used as part of ransomware attack chains targeting NAS devices, where the XSS attack serves as an initial access or credential theft mechanism. The EPSS percentile of 96.7% indicates high real-world exploitation activity.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2018-19953 by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 14, 2022. CISA has flagged this vulnerability as associated with ransomware campaigns, confirming its use in attacks that encrypt data on NAS devices and demand ransom payment. The EPSS percentile of 96.7% indicates high exploitation likelihood. QNAP NAS devices have been a frequent target for ransomware operators due to their role as centralized data storage, and XSS vulnerabilities like CVE-2018-19953 provide a vector for stealing administrative credentials that enable further exploitation.

Remediation

  1. Apply firmware updates from QNAP that address CVE-2018-19953. CISA's required action is to apply updates per vendor instructions.
  2. If the NAS device is accessible from the internet, restrict external access immediately by disabling port forwarding for the web management interface and File Station.
  3. Enable HTTPS for the QNAP web interface and configure Content Security Policy (CSP) headers if supported to limit the impact of XSS attacks.
  4. Review NAS user accounts for any unauthorized accounts or suspicious activity that may indicate prior exploitation.
  5. Implement network segmentation to isolate the NAS device from other critical systems, and configure firewall rules to allow access only from trusted internal networks.

Technical Details

CVE-2018-19953 is a cross-site scripting vulnerability in the File Station component of QNAP NAS devices. File Station provides a web-based file management interface that allows users to browse, upload, download, and manage files stored on the NAS through a web browser. The vulnerability exists because the File Station web application fails to properly sanitize or encode user-controlled input before including it in dynamically generated HTML pages. An attacker can craft a request containing malicious JavaScript that, when rendered by the File Station interface, executes in the context of the authenticated user's browser session. The injected script has full access to the Document Object Model (DOM) of the File Station page, including any authentication cookies, CSRF tokens, and file management functionality accessible through the web interface.

Frequently Asked Questions

Is CVE-2018-19953 being actively exploited?

Yes, CISA has confirmed active exploitation of CVE-2018-19953 and has flagged it as associated with ransomware campaigns targeting NAS devices. The EPSS percentile of 96.7% confirms high exploitation probability. QNAP NAS devices have been frequent targets for ransomware operators.

What products are affected by CVE-2018-19953?

CVE-2018-19953 affects QNAP Network Attached Storage (NAS) devices, specifically the File Station web application component. All QNAP NAS models running firmware versions vulnerable to this XSS flaw are affected until updated.

How do I fix CVE-2018-19953?

Apply the latest firmware updates from QNAP that address CVE-2018-19953. Additionally, restrict external access to the NAS web interface by disabling port forwarding and ensure the device is only accessible from trusted internal networks.

How severe is CVE-2018-19953?

CVE-2018-19953 is a cross-site scripting vulnerability with an EPSS percentile of 96.7% and a confirmed ransomware association. While XSS vulnerabilities are often considered lower severity in isolation, this vulnerability's role in ransomware attack chains targeting NAS devices makes it a critical security issue that requires immediate patching.

CVSS Score

6.1
MEDIUM(6.1)

EPSS Score

EPSS Score23.89%
EPSS Percentile97.6%

Dates

PublishedOctober 28, 2020
Last ModifiedAugust 13, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.