Junglewise Threat Intelligence

CVE-2019-7194: QNAP Photo Station Path Traversal Vulnerability

CVE-2019-7194 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-08

Technologies: QNAP Photo Station. Vendors: QNAP Systems, Inc., QNAP.

Executive brief

A path traversal vulnerability in QNAP Photo Station allows remote attackers to access or modify system files via external control of file names or paths. This vulnerability can be leveraged to achieve remote command execution.

Affected products

  • QNAP Systems, Inc. Photo Station < 5.2.11 (on QTS 4.2.6)
  • QNAP Systems, Inc. Photo Station < 5.4.9 (on QTS 4.3.0 - 4.3.3)
  • QNAP Systems, Inc. Photo Station < 5.7.10 (on QTS 4.3.4 - 4.4.0)
  • QNAP Systems, Inc. Photo Station < 6.0.3 (on QTS 4.4.1)

Timeline

  • 2019-12-05: disclosed: NVD Published Date
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-05-28: other: Public exploit published on Packet Storm Security

Related threats