CVE-2018-19945 is a critical vulnerability affecting earlier QNAP QTS versions 4.3.4 to 4.3.6, stemming from improper pathname limitations. This allows unauthenticated attackers to rename arbitrary files on the target system, leading to high integrity and availability impacts. While QNAP has released patches, there is no public exploit code, active exploitation, or significant community discussion reported for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.3.4, < 4.3.4.0899CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.5, < 4.3.6.0895CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.