ZeroHour

CVE-2019-7194

KEV ransomware PoC large

Unauthenticated Path Traversal in QNAP Photo Station Enables File Access/RCE

CISA: QNAP Photo Station Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
83%p100
Published
()
KEV added
AI analysis

CVE-2019-7194 is a path traversal flaw (CWE-22, external control of file name or path) in QNAP Photo Station, the web-based photo application bundled with QNAP NAS devices. Because vulnerable code lets remote, unauthenticated attackers control file paths in crafted requests, they can read or modify arbitrary system files over the network with no privileges or user interaction (CVSS 3.1: 9.8). With the ability to write system files, attackers can escalate to full remote command execution — a public proof of concept demonstrates RCE against QTS with Photo Station 6.0.3 — and the flaw is known to be used in ransomware campaigns. Any QNAP NAS running Photo Station is affected, particularly devices whose web application is exposed to the internet. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and EPSS assigns an 83.1% probability of exploitation within 30 days (100th percentile).

What to do: Update Photo Station to the latest version available via the QTS App Center, per QNAP's advisory, on every NAS. Disable Photo Station or remove firewall/port-forwarding rules that expose NAS web applications directly to the internet, since unauthenticated remote access is the attack vector. Given known ransomware use, check exposed devices for signs of compromise (unexpected files, enabled maintenance mode, or encryption activity) before and after patching.

Affected
QNAP Photo Station
Estimated exposure
large≈tens of thousands of internet-exposed QNAP NAS devices running Photo Station (estimate) — QNAP's installed base is in the millions of NAS devices and public internet scans show hundreds of thousands of exposed QNAP devices, but only the subset with Photo Station enabled is exploitable, an order of magnitude consistent with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CISA Known Exploited Vulnerability
Affected
QNAP Photo Station
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
photo station
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news