ZeroHour

CVE-2019-7195

KEV ransomware PoC large

Path Traversal in QNAP Photo Station Enables Unauthenticated RCE

CISA: QNAP Photo Station Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2019-7195 is a path traversal flaw (CWE-22, external control of file name or path) in QNAP's Photo Station multimedia application, in which an attacker-supplied file name or path is not properly validated. Per its CVSS vector (AV:N/AC:L/PR:N/UI:N), it is exploited over the network with no authentication and no user interaction, letting an unauthenticated remote attacker access or modify system files; a public proof of concept demonstrates chaining the flaw to full remote command execution against QTS with Photo Station 6.0.3. Successful exploitation gives an attacker the ability to read, alter, and execute code on the NAS, which has been leveraged for ransomware deployments. Any QNAP NAS device running Photo Station, particularly with the web interface reachable from the internet, is affected. Exploitation is confirmed in the wild: the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and EPSS estimates an 89.7% probability of exploitation in the next 30 days.

What to do: Update Photo Station to the latest version available for your QTS release, following QNAP's instructions (the action CISA requires for KEV entries); if patching is not immediately possible, restrict access to the Photo Station web interface to trusted networks or a VPN. Because ransomware use is known, also check exposed NAS for signs of compromise after patching, such as unexpected files, unknown user accounts, or unfamiliar scheduled tasks.

Affected
QNAP Photo StationPrior Photo Station releases (public PoC tested against Photo Station 6.0.3 on QTS); QNAP recommends updating Photo Station to the latest versions
Estimated exposure
large≈tens of thousands (up to ~100,000) of internet-exposed QNAP Photo Station instances (public scans show hundreds of thousands of internet-visible QNAP NAS… — Estimated from public internet scan counts of exposed QNAP NAS devices combined with the fact that Photo Station is a widely bundled/installed multimedia app on QTS, with only a subset of exposed devices running it with its web interface…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CISA Known Exploited Vulnerability
Affected
QNAP Photo Station
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
photo station
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news