Skip to main content

Photo Station vulnerabilities

4 published alerts for QNAP Photo Station.

Actively exploited (KEV)Ransomware

CVE-2022-27593

QNAP Photo Station Externally Controlled Reference Vulnerability

QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-27593). Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign. CISA remediation due date: 2022-09-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-7195

QNAP Photo Station Path Traversal Vulnerability

QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7195). QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-7194

QNAP Photo Station Path Traversal Vulnerability

QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7194). QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-7192

QNAP Photo Station Improper Access Control Vulnerability

QNAP Photo Station is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-7192). QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system. CISA remediation due date: 2022-06-22. If you need help checking exposure, call (864) 335-9223.