CVE-2018-19953 is a cross-site scripting (XSS) vulnerability affecting QNAP QTS, which could allow remote attackers to inject malicious code. This vulnerability has a CVSS score of 6.1 (Medium) and a FAUCET Risk Score of 99/100, indicating a significant risk due to its network-based attack vector and low attack complexity, potentially leading to partial confidentiality and integrity impacts. Notably, this CVE is actively exploited, specifically in known eCh0raix ransomware campaigns targeting QNAP NAS devices, despite no public Metasploit or ExploitDB modules. The vulnerability has garnered considerable community discussion, with 11 mentions, and has been addressed by QNAP in various QTS versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.6CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.1.0013, < 4.3.3.1161CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.4, < 4.3.4.1190CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.6, < 4.3.6.1218CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.4.0, < 4.4.1.1201CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.