vulnerability
QNAP QTS: CVE-2018-19945: Improper Limitation of a Pathname to a Restricted Directory in QTS
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:P/A:C) | Dec 30, 2020 | Aug 4, 2025 | Oct 16, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:C)
Published
Dec 30, 2020
Added
Aug 4, 2025
Modified
Oct 16, 2025
Description
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. We have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.
Solution
qnap-qts-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.