CISA Known Exploited Vulnerability

CVE-2018-19949 Ransomware

QNAP · Network Attached Storage (NAS)

QNAP NAS File Station Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20, CWE-77, CWE-78
Ransomware Known

CISA description

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

Required action

Apply updates per vendor instructions.