LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-19943: QNAP NAS File Station Cross-Site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 24, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-19943 to its Known Exploited Vulnerabilities catalog on May 24, 2022, with a federal patch deadline of Jun 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

CVE-2018-19943 is a cross-site scripting vulnerability in the File Station component of QNAP Network Attached Storage (NAS) devices. It could allow remote attackers to inject malicious code. This matters because QNAP NAS systems often hold shared files, backups, and business data; successful abuse of File Station XSS can lead to session compromise, credential theft, or further actions on the device. CISA notes known ransomware use associated with this issue, so organizations running QNAP NAS should treat it as a priority for inventory and remediation.

How it works

The flaw falls under CWE-79 and CWE-80: improper neutralization of input during web page generation, allowing cross-site scripting. In products like QNAP File Station, which provides a web interface for file browsing and management, unsanitized input can be reflected or stored so that a victim’s browser executes attacker-supplied script in the context of the NAS web application.

An attacker typically needs a way to supply crafted input that reaches File Station and then trick an authenticated user (or an admin session) into loading a page that includes that input. Once script runs in the victim’s browser, it can act with the user’s privileges on the NAS interface—for example reading session tokens, performing actions the user can perform, or pivoting toward other stored data. Exact injection points and request details are not provided here; confirm mechanics and preconditions against the vendor advisory.

Am I affected? How to find it in your systems

QNAP NAS appliances are commonly deployed for file sharing, backup targets, media storage, and small-office or departmental storage, often reachable on internal networks and sometimes exposed via VPN, reverse proxy, or direct internet access. File Station is the web-based file manager on these devices.

How to remediate

Patch first. Apply the updates QNAP provides for this vulnerability, following the vendor’s instructions exactly as CISA requires. Confirm the fixed package or firmware level in the official advisory before and after installation, and reboot or restart services only as directed.

If you can't patch immediately

Reduce exposure until you can apply the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, can lead to data theft or encryption. If you suspect compromise of a QNAP NAS, isolate the device, preserve evidence, follow your incident response process, and assess what shares and backups may have been accessible. You can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or identities appear in public breach sets, then reset passwords and review access accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQNAP · Network Attached Storage (NAS)
WeaknessCWE-79
Added to CISA KEVMay 24, 2022
Federal patch deadlineJun 14, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities