---
id: CVE-2018-19949
title: >-
  If exploited, this command injection vulnerability could allow remote
  attackers to run arbitrary commands
summary: >-
  If exploited, this command injection vulnerability could allow remote
  attackers to run arbitrary commands. QNAP has already fixed the issue in the
  following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on
  build 20200130…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
  - CWE-77
  - CWE-78
  - CWE-77
vendor: qnap
product: qts
affected:
  - qts < 4.2.6
  - 'qts >= 4.3.1.0013, < 4.3.3.1161'
  - 'qts >= 4.3.4, < 4.3.4.1190'
  - 'qts >= 4.3.6, < 4.3.6.1218'
  - 'qts >= 4.4.0, < 4.4.1.1201'
  - 'qts >= 4.4.2, < 4.4.2.1231'
  - qts = 4.2.6
patched:
  - qts 4.4.2.1231
published: '2020-10-28'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-19949'
references:
  - url: 'https://www.qnap.com/zh-tw/security-advisory/qsa-20-01'
    label: security@qnapsecurity.com.tw
  - url: 'https://www.qnap.com/zh-tw/security-advisory/qsa-20-01'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19949
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.24449
epssPercentile: 0.97815
kev: true
kevDateAdded: '2022-05-24'
kevDueDate: '2022-06-14'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-13T06:00:54.946Z'
---

## Overview

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

## Affected

- `qts < 4.2.6`
- `qts >= 4.3.1.0013, < 4.3.3.1161`
- `qts >= 4.3.4, < 4.3.4.1190`
- `qts >= 4.3.6, < 4.3.6.1218`
- `qts >= 4.4.0, < 4.4.1.1201`
- `qts >= 4.4.2, < 4.4.2.1231`
- `qts = 4.2.6`

## Remediation

Upgrade past the affected range:

- `qts 4.4.2.1231`
