CVE-2019-7195
KEV ransomware PoC largePath Traversal in QNAP Photo Station Enables Unauthenticated RCE
CISA: QNAP Photo Station Path Traversal Vulnerability
CVE-2019-7195 is a path traversal flaw (CWE-22, external control of file name or path) in QNAP's Photo Station multimedia application, in which an attacker-supplied file name or path is not properly validated. Per its CVSS vector (AV:N/AC:L/PR:N/UI:N), it is exploited over the network with no authentication and no user interaction, letting an unauthenticated remote attacker access or modify system files; a public proof of concept demonstrates chaining the flaw to full remote command execution against QTS with Photo Station 6.0.3. Successful exploitation gives an attacker the ability to read, alter, and execute code on the NAS, which has been leveraged for ransomware deployments. Any QNAP NAS device running Photo Station, particularly with the web interface reachable from the internet, is affected. Exploitation is confirmed in the wild: the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and EPSS estimates an 89.7% probability of exploitation in the next 30 days.
What to do: Update Photo Station to the latest version available for your QTS release, following QNAP's instructions (the action CISA requires for KEV entries); if patching is not immediately possible, restrict access to the Photo Station web interface to trusted networks or a VPN. Because ransomware use is known, also check exposed NAS for signs of compromise after patching, such as unexpected files, unknown user accounts, or unfamiliar scheduled tasks.
| QNAP Photo Station | Prior Photo Station releases (public PoC tested against Photo Station 6.0.3 on QTS); QNAP recommends updating Photo Station to the latest versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- Affected
- QNAP Photo Station
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- photo station
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H