Executive brief
QNAP NAS devices running Photo Station contain an improper access control vulnerability. This flaw allows remote, unauthenticated attackers to gain unauthorized access to the system, potentially leading to remote command execution.
Affected products
- QNAP Systems, Inc. Photo Station < 5.2.11, < 5.4.9, < 5.7.10, < 6.0.3
- QNAP Systems, Inc. QTS 4.2.6, 4.3.0 - 4.3.3, 4.3.4 - 4.4.0, 4.4.1
Timeline
- 2019-11-25: advisory: Vendor advisory NAS-201911-25 published by QNAP.
- 2019-12-05: disclosed: NVD Published Date.
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-06-08: exploited: Confirmed as exploited in the wild per CISA KEV catalog.