{"id":"CVE-2018-19949","title":"If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands","summary":"If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-20","CWE-77","CWE-78","CWE-77"],"vendor":"qnap","product":"qts","affected":["qts < 4.2.6","qts >= 4.3.1.0013, < 4.3.3.1161","qts >= 4.3.4, < 4.3.4.1190","qts >= 4.3.6, < 4.3.6.1218","qts >= 4.4.0, < 4.4.1.1201","qts >= 4.4.2, < 4.4.2.1231","qts = 4.2.6"],"patched":["qts 4.4.2.1231"],"published":"2020-10-28","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-19949","references":[{"url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-01","label":"security@qnapsecurity.com.tw"},{"url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-01","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19949","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.24449,"epssPercentile":0.97815,"kev":true,"kevDateAdded":"2022-05-24","kevDueDate":"2022-06-14","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-13T06:00:54.946Z","slug":"CVE-2018-19949","body":"## Overview\n\nIf exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.\n\n## Affected\n\n- `qts < 4.2.6`\n- `qts >= 4.3.1.0013, < 4.3.3.1161`\n- `qts >= 4.3.4, < 4.3.4.1190`\n- `qts >= 4.3.6, < 4.3.6.1218`\n- `qts >= 4.4.0, < 4.4.1.1201`\n- `qts >= 4.4.2, < 4.4.2.1231`\n- `qts = 4.2.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `qts 4.4.2.1231`","depth":"hadal","depthScore":89,"depthScoreParts":{"impact":53.9,"likelihood":4.9,"exploitation":25,"ransomware":5},"changes":[]}