Junglewise Threat Intelligence

CVE-2019-7195: QNAP Photo Station Path Traversal Vulnerability

CVE-2019-7195 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-08

Technologies: QNAP Photo Station. Vendors: QNAP Systems, Inc., QNAP.

Executive brief

QNAP Photo Station contains a path traversal vulnerability due to improper limitation of a pathname to a restricted directory. Remote attackers can exploit this to access or modify sensitive system files without authentication.

Affected products

  • QNAP Systems, Inc. Photo Station < 5.2.11, < 5.4.9, < 5.7.10, < 6.0.3
  • QNAP Systems, Inc. QTS 4.2.6, 4.3.0 - 4.3.3, 4.3.4 - 4.4.0, 4.4.1

Timeline

  • 2019-12-05: disclosed: NVD Published Date
  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-05-27: other: Public exploit released on Packet Storm Security

Related threats