Vulnerability record · CVE-2018-19943 · published 28 October 2020
CVE-2018-19943: QNAP QTS File Station cross-site scripting
Qnap · Qts
QNAP QTS contains a cross-site scripting flaw in File Station that lets a remote attacker inject malicious code. It matters because the vendor has fixed it across multiple QTS branches and CISA lists it as exploited in the wild.
Description
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is in CISA KEV with known ransomware use and a high EPSS percentile, though the CVSS score is only medium and exploitation requires user interaction.
What it is
QNAP QTS contains a cross-site scripting flaw in File Station that lets a remote attacker inject malicious code. It matters because the vendor has fixed it across multiple QTS branches and CISA lists it as exploited in the wild.
Impact
An attacker can run script in a victim's browser session in the context of the QNAP interface, potentially stealing session data or performing actions as the user. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network through the QTS File Station web interface. The vector requires low privileges and user interaction, so the attacker needs some authenticated access and must lure a user into triggering the payload.
Exploitation
CISA added it to KEV on 2022-05-24 with a 2022-06-14 due date and flags known ransomware campaign use. EPSS is 0.17705 (97th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade QTS to a fixed build: 4.4.2.1270, 4.4.1.1261, 4.3.6.1263, 4.3.4.1282, 4.3.3.1252, or 4.2.6 build 20200421 or later.
- If immediate patching is not possible, restrict network access to the QTS management and File Station interfaces.
- Enforce least privilege and avoid granting unnecessary accounts access to File Station.
- Review QNAP security advisory QSA-20-01 for any additional vendor guidance.
Detection
- Inspect web and proxy logs for script payloads or unusual parameters targeting File Station endpoints.
- Monitor for anomalous authenticated sessions or actions originating from File Station.
- Correlate QTS access logs with known exploitation indicators and alert on suspicious request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-19943 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "QNAP NAS File Station Cross-Site Scripting Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | Vendor Advisory |
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19943 | US Government Resource |
Track CVE-2018-19943 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19943), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.