Executive brief
QNAP Photo Station contains a path traversal vulnerability due to improper limitation of a pathname to a restricted directory. Remote attackers can exploit this to access or modify sensitive system files without authentication.
Affected products
- QNAP Systems, Inc. Photo Station < 5.2.11, < 5.4.9, < 5.7.10, < 6.0.3
- QNAP Systems, Inc. QTS 4.2.6, 4.3.0 - 4.3.3, 4.3.4 - 4.4.0, 4.4.1
Timeline
- 2019-12-05: disclosed: NVD Published Date
- 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-05-27: other: Public exploit released on Packet Storm Security