Vulnerability record · CVE-2018-19953 · published 28 October 2020
CVE-2018-19953: QNAP QTS File Station cross-site scripting flaw
Qnap · Qts
QNAP QTS contains a cross-site scripting vulnerability in File Station that lets remote attackers inject malicious code. It matters because the flaw is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, so unpatched NAS devices are a live target.
Description
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityIt is a medium-CVSS XSS but is in CISA KEV with known ransomware use and a high EPSS percentile, so exploitation is likely and impact on NAS data is serious.
What it is
QNAP QTS contains a cross-site scripting vulnerability in File Station that lets remote attackers inject malicious code. It matters because the flaw is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, so unpatched NAS devices are a live target.
Impact
An attacker can run script in the context of a victim's browser session, potentially stealing session data or performing actions as the logged-in user. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), typically a victim visiting or clicking a crafted link or page. No authentication is needed to deliver the attack, only the victim's action.
Exploitation
CISA added it to KEV on 2022-05-24 with a 2022-06-14 remediation due date and flags known ransomware campaign use. EPSS 30-day probability is about 0.239 (97.7th percentile), indicating high predicted exploitation activity.
What to do
- Upgrade QTS to a fixed build: 4.4.2.1231 (20200302), 4.4.1.1201 (20200130), 4.3.6.1218 (20200214), 4.3.4.1190 (20200107), 4.3.3.1161 (20200109), or 4.2.6 (20200109).
- If immediate patching is not possible, restrict network exposure of QTS/File Station to trusted networks and disable remote access.
- Apply the vendor advisory QSA-20-01 guidance and verify the installed QTS build after upgrading.
- Treat NAS management interfaces as high-value assets and enforce strong authentication and monitoring given the KEV ransomware association.
Detection
- Review QTS/File Station access logs for suspicious or encoded script payloads in request parameters and URLs.
- Monitor for unexpected outbound connections or file encryption activity on QNAP NAS hosts that could indicate post-exploitation ransomware behavior.
- Audit installed QTS versions across the fleet against the fixed builds and flag any host still on an older build.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-19953 to the Known Exploited Vulnerabilities catalog on 24 May 2022 as "QNAP NAS File Station Cross-Site Scripting Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | Vendor Advisory |
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19953 | US Government Resource |
Track CVE-2018-19953 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19953), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.