LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-19949: QNAP NAS File Station Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 24, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-19949 to its Known Exploited Vulnerabilities catalog on May 24, 2022, with a federal patch deadline of Jun 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

CVE-2018-19949 is a command injection vulnerability in the File Station component of QNAP Network Attached Storage (NAS) devices. It can allow remote attackers to run commands on the affected system. Because this class of flaw has been tied to ransomware activity, organizations running QNAP NAS should treat it as a priority for inventory, patching, and monitoring.

Public detail is limited to the vendor and CISA descriptions; confirm exact impact, fixed builds, and any prerequisites against the official QNAP advisory before acting.

How it works

The weakness is categorized under improper input validation (CWE-20) and command injection (CWE-77/CWE-78). In products that expose file-management interfaces such as File Station, user-supplied input is sometimes passed to operating-system command interpreters without adequate sanitization or parameterization.

An attacker who can reach the vulnerable File Station functionality may craft requests that cause the NAS to execute attacker-chosen commands in the context of the service account. Successful abuse typically yields the ability to read or alter files, create persistence, or stage further payloads. Exact request format, authentication requirements, and reachable surfaces are not detailed in the provided facts and must be taken from the vendor advisory.

Am I affected? How to find it in your systems

QNAP NAS appliances are commonly deployed for file sharing, backup targets, media libraries, and departmental storage, both on internal networks and, in some cases, with remote access enabled. Inventory every QNAP device by:

Telemetry that may indicate exploitation attempts includes unusual process executions spawned by the web or File Station services, unexpected outbound connections from the NAS, sudden creation of encrypted files or ransom notes, and authentication or application logs showing anomalous File Station requests. Because the facts do not list specific indicators of compromise, treat any unexplained command activity on the device as suspicious and investigate promptly.

How to remediate

Patch first. Apply the updates published by QNAP for this vulnerability exactly as described in the vendor advisory and follow CISA’s required action to apply updates per vendor instructions. After upgrading:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not replace the official update.

If your data may have been exposed

Command-injection flaws on NAS devices have been used by ransomware operators; if the device was reachable and unpatched during the period of exposure, assume an attacker could have executed commands, exfiltrated data, or staged encryption. Isolate the affected system, preserve logs and disk images for forensics, reset credentials, and restore from known-good backups after confirming they are clean. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQNAP · Network Attached Storage (NAS)
WeaknessCWE-20
Added to CISA KEVMay 24, 2022
Federal patch deadlineJun 14, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities