CVE-2019-7194criticalunder attackransomwareCWE-22

CVE-2019-7194: critical vulnerability in QNAP NAS devices running Photo Station

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 83%
from disclosure to weapon0 days
Published on NVDDec 5
metasploitNov 25
CISA KEV+916d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-06-22

Apply updates per vendor instructions.

In short

A flaw in Photo Station lets attackers read or change important system files on a QNAP device by controlling file paths. This is critical because it can compromise the entire system's security and data.

Technical detail

Path traversal vulnerability (CWE-22) in QNAP Photo Station allows remote, unauthenticated attackers to access or modify arbitrary system files via unvalidated file path parameters. No special preconditions are required; exploitation results in complete system compromise with high impact on confidentiality, integrity, and availability.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.