EXPOSURES › CVE-2018-19943
CVE-2018-19943
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQNAP NAS devices were vulnerable to cross-site scripting, exploited in the wild, and linked to ransomware activity.
A cross-site scripting vulnerability in QNAP File Station allowed remote code injection, potentially leading to data compromise and ransomware infection. DIB organizations using QNAP NAS devices must immediately patch and review access controls to mitigate risk and maintain CMMC compliance. Failure to address this could result in significant penalties and reputational damage.
Shame score — The vulnerability was actively exploited and linked to ransomware, indicating a serious failure in secure coding practices and a significant risk to data integrity.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.