Vulnerability record · CVE-2018-19949 · published 28 October 2020
CVE-2018-19949: QNAP QTS File Station command injection allows remote code execution
Qnap · Qts
QNAP QTS contains a command injection flaw in File Station that lets remote attackers run arbitrary commands on the NAS. It is remotely reachable without authentication or user interaction and carries a critical CVSS score of 9.8. QNAP has released fixed QTS builds, and CISA lists it as exploited in ransomware campaigns.
Description
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCritical CVSS 9.8, no authentication or interaction required, and confirmed exploitation in ransomware campaigns per CISA KEV.
What it is
QNAP QTS contains a command injection flaw in File Station that lets remote attackers run arbitrary commands on the NAS. It is remotely reachable without authentication or user interaction and carries a critical CVSS score of 9.8. QNAP has released fixed QTS builds, and CISA lists it as exploited in ransomware campaigns.
Impact
An attacker gains arbitrary command execution on the NAS, which can lead to full device compromise, data theft or encryption, and use of the device as a foothold into the network.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so it can be triggered directly over the network against the File Station component. No authentication is required per the CVSS vector.
Exploitation
CISA added it to KEV on 2022-05-24 with known ransomware campaign use, and EPSS shows a 24.4% 30-day probability (97.8th percentile), indicating active exploitation. References are vendor advisories and the CISA KEV entry.
What to do
- Upgrade QTS to a fixed build: 4.4.2.1231 (20200302), 4.4.1.1201 (20200130), 4.3.6.1218 (20200214), 4.3.4.1190 (20200107), 4.3.3.1161 (20200109), or 4.2.6 (20200109) or later.
- If patching is not immediately possible, disable or restrict access to File Station and block external exposure of the QTS management interface.
- Segment NAS devices from untrusted networks and enforce access only from trusted management networks or VPN.
- Review NAS accounts and logs for signs of compromise, and back up data offline given documented ransomware use.
Detection
- Monitor QTS and File Station logs for unexpected command execution or abnormal process spawning from web service processes.
- Alert on unusual outbound connections or file encryption activity on NAS hosts.
- Hunt for known exploitation indicators against File Station endpoints in web access logs, including anomalous requests to File Station paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-19949 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "QNAP NAS File Station Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | Vendor Advisory |
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19949 | US Government Resource |
Track CVE-2018-19949 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19949), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.