CVE-2019-7194
KEV ransomware PoC largeUnauthenticated Path Traversal in QNAP Photo Station Enables File Access/RCE
CISA: QNAP Photo Station Path Traversal Vulnerability
CVE-2019-7194 is a path traversal flaw (CWE-22, external control of file name or path) in QNAP Photo Station, the web-based photo application bundled with QNAP NAS devices. Because vulnerable code lets remote, unauthenticated attackers control file paths in crafted requests, they can read or modify arbitrary system files over the network with no privileges or user interaction (CVSS 3.1: 9.8). With the ability to write system files, attackers can escalate to full remote command execution — a public proof of concept demonstrates RCE against QTS with Photo Station 6.0.3 — and the flaw is known to be used in ransomware campaigns. Any QNAP NAS running Photo Station is affected, particularly devices whose web application is exposed to the internet. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and EPSS assigns an 83.1% probability of exploitation within 30 days (100th percentile).
What to do: Update Photo Station to the latest version available via the QTS App Center, per QNAP's advisory, on every NAS. Disable Photo Station or remove firewall/port-forwarding rules that expose NAS web applications directly to the internet, since unauthenticated remote access is the attack vector. Given known ransomware use, check exposed devices for signs of compromise (unexpected files, enabled maintenance mode, or encryption activity) before and after patching.
| QNAP Photo Station | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- Affected
- QNAP Photo Station
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- photo station
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H