Executive brief
An externally controlled reference to a resource vulnerability in QNAP Photo Station allows remote attackers to modify system files. This vulnerability has been actively exploited in the wild, specifically in Deadbolt ransomware campaigns.
Affected products
- QNAP Photo Station 6.1.2 (QTS 5.0.1); 6.0.22 (QTS 5.0.0/4.5.x); 5.7.18 (QTS 4.3.6); 5.4.15 (QTS 4.3.3); 5.2.14 (QTS 4.2.6)
Timeline
- 2022-09-08: disclosed
- 2022-09-08: advisory
- 2022-09-08: kev added: Added to CISA KEV catalog
- 2022-09-08: exploited: Observed in Deadbolt ransomware campaign