CVE-2018-19949 is a critical command injection vulnerability affecting QNAP QTS network-attached storage (NAS) devices. This flaw allows remote, unauthenticated attackers to execute arbitrary commands on affected systems. With a CVSS score of 9.8 (Critical), it poses a significant risk due to its low attack complexity and complete compromise potential (confidentiality, integrity, and availability). This vulnerability is actively exploited, notably in eCh0raix ransomware campaigns, and has garnered considerable community and media attention. QNAP has released patches for various QTS versions to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.6CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.1.0013, < 4.3.3.1161CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.4, < 4.3.4.1190CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.6, < 4.3.6.1218CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.4.0, < 4.4.1.1201CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.