Skip to content
COOEY

EXPOSURES › CVE-2018-19953

CVE-2018-19953

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-19953 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatched

QNAP NAS File Station XSS vulnerability allowed remote attackers to inject malicious code, linked to ransomware attacks.

A cross-site scripting flaw in QNAP NAS File Station enabled remote attackers to inject malicious scripts, directly tied to ransomware incidents. DIB organizations must patch NAS firmware immediately and monitor for similar exploits, as unpatched hardware can become ransomware entry points. This failure highlights the risk of relying on unpatched network storage devices in critical infrastructure.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating negligent patching and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.