Executive brief
A path traversal vulnerability in QNAP Photo Station allows remote attackers to access or modify system files via external control of file names or paths. This vulnerability can be leveraged to achieve remote command execution.
Affected products
- QNAP Systems, Inc. Photo Station < 5.2.11 (on QTS 4.2.6)
- QNAP Systems, Inc. Photo Station < 5.4.9 (on QTS 4.3.0 - 4.3.3)
- QNAP Systems, Inc. Photo Station < 5.7.10 (on QTS 4.3.4 - 4.4.0)
- QNAP Systems, Inc. Photo Station < 6.0.3 (on QTS 4.4.1)
Timeline
- 2019-12-05: disclosed: NVD Published Date
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-05-28: other: Public exploit published on Packet Storm Security