LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-7195: QNAP Photo Station Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-7195 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

CVE-2019-7195 is a path traversal vulnerability in QNAP Photo Station that lets remote attackers control file names or paths. On affected QNAP devices this can allow access to or modification of system files. The weakness has been used in ransomware activity, so organizations running Photo Station should treat it as a priority for inventory and remediation.

CISA advises applying updates according to the vendor’s instructions. Exact affected builds, fixed releases, and any configuration prerequisites must be confirmed against the current QNAP advisory.

How it works

The flaw is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In products that accept user-supplied path or filename input, insufficient validation can let an attacker insert directory-traversal sequences. When the application then opens, reads, or writes the resulting path, the attacker can reach files outside the intended Photo Station directory tree.

On a QNAP device running Photo Station, a remote attacker who can reach the vulnerable interface may therefore read or alter system files that the Photo Station process is permitted to touch. Public detail beyond this class of abuse is limited; defenders should not assume any particular exploit payload or authentication requirement without checking the vendor advisory.

Am I affected? How to find it in your systems

QNAP Photo Station is typically installed on QNAP NAS appliances used for photo storage, sharing, and media management. It may be enabled by default or added later through the QNAP App Center.

How to remediate

Patching is the primary remediation. Apply the Photo Station (or QTS/QuTS) update that QNAP released to address CVE-2019-7195, following the vendor’s installation instructions exactly. After updating, verify the new version is reported by the App Center or system firmware page.

Once the patch is in place, harden the broader class of path-traversal risk:

If you can't patch immediately

When an immediate update is not feasible, apply compensating controls to reduce exposure until the patch can be installed:

These measures lower risk but do not eliminate it; schedule the official update as soon as operationally possible.

If your data may have been exposed

Actively exploited vulnerabilities, including those known to be used by ransomware operators, frequently lead to data theft or encryption. If logs, external notifications, or ransomware notes suggest your QNAP device was compromised, treat the incident as a potential breach: isolate the system, preserve forensic images, reset credentials, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in public dumps, then force password changes and enable multi-factor authentication on any confirmed exposures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQNAP · Photo Station
WeaknessCWE-22
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities