CVE-2018-19949: QNAP NAS File Station Command Injection Vulnerability
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Other sources
A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.4.2.1231Patch build 20200302 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.4.1.1201Patch build 20200130 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.3.6.1218Patch build 20200214 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.3.4.1190Patch build 20200107 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.3.3.1161Patch build 20200109 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.2.6Patch build 20200109
Event History
Frequently Asked Questions
What is CVE-2018-19949?
CVE-2018-19949 is a command injection vulnerability found in QNAP NAS File Station.
How severe is CVE-2018-19949?
CVE-2018-19949 has a severity rating of 9.8, which is considered critical.
How can CVE-2018-19949 be exploited?
CVE-2018-19949 can be exploited by remote attackers to run arbitrary commands.
Which QTS versions have fixed CVE-2018-19949?
CVE-2018-19949 has been fixed in the following QTS versions: QTS 4.4.2.1231 (build 20200302), QTS 4.4.1.1201 (build 20200130), QTS 4.3.6.1218 (build 20200214), QTS 4.3.4.1190 (build 20200329).
Where can I find more information about CVE-2018-19949?
You can find more information about CVE-2018-19949 and the fix in the QNAP security advisory QSA-20-01.