CVE-2018-19949CISA KEVEPSS p97.6%

CVE-2018-19949QNAP NAS File Station Command Injection Vulnerability

QNAP / Network Attached Storage (NAS)

Description

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

Scoring

EPSS24.45% probability of exploitation · percentile 97.6% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-05-24

(incoming)1

TypeTargetConfidenceTier
KEVEntryQNAP NAS File Station Command Injection Vulnerabilitykev-cve-2018-199490%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
CVE
QNAP NAS File Station Cross-Site Scripting Vulnerability
CVE
QNAP QTS Improper Input Validation Vulnerability
CVE
QNAP Photo Station Improper Access Control Vulnerability
CVE
QNAP Photo Station Path Traversal Vulnerability
CVE
QNAP VioStor NVR OS Command Injection Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.