CISA Known Exploited Vulnerability

CVE-2018-19953 Ransomware

QNAP · Network Attached Storage (NAS)

QNAP NAS File Station Cross-Site Scripting Vulnerability

Date added
BOD 22-01 due date
CWE CWE-79, CWE-80
Ransomware Known

CISA description

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

Required action

Apply updates per vendor instructions.