EXPOSURES › CVE-2018-19953
CVE-2018-19953
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQNAP NAS File Station XSS vulnerability allowed remote attackers to inject malicious code, linked to ransomware attacks.
A cross-site scripting flaw in QNAP NAS File Station enabled remote attackers to inject malicious scripts, directly tied to ransomware incidents. DIB organizations must patch NAS firmware immediately and monitor for similar exploits, as unpatched hardware can become ransomware entry points. This failure highlights the risk of relying on unpatched network storage devices in critical infrastructure.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating negligent patching and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.