LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-27593: QNAP Photo Station Externally Controlled Reference Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 8, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-27593 to its Known Exploited Vulnerabilities catalog on Sep 8, 2022, with a federal patch deadline of Sep 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This…

CVE-2022-27593 is an externally controlled reference vulnerability in QNAP Photo Station software that runs on certain QNAP network-attached storage (NAS) devices. When Photo Station is exposed to the internet, an attacker can abuse the flaw to modify system files on the device. This matters because the vulnerability has been observed in a Deadbolt ransomware campaign, giving opportunistic attackers a path to compromise storage systems that often hold business or personal data.

IT and security teams should treat internet-facing QNAP NAS instances running Photo Station as high priority for inventory and remediation. Confirm all product-specific details against the vendor advisory, as public information on exact configurations is limited.

How it works

The underlying weakness is CWE-610, an externally controlled reference to a resource. In this class of flaw, the application accepts attacker-supplied input that influences which resource (such as a file or path) the software accesses or acts upon. On affected QNAP Photo Station installations, this control can be leveraged to modify system files.

An attacker who can reach the Photo Station service over the network supplies crafted input that redirects the application's resource handling. Successful abuse allows unauthorized changes to system files rather than merely reading data. Because the service may run with elevated privileges on the NAS, the impact can extend beyond the Photo Station application itself. Exact request formats and preconditions are not detailed in the available summary; defenders must rely on the vendor advisory for any technical indicators of compromise.

Am I affected? How to find it in your systems

QNAP Photo Station is a photo-management application commonly installed on QNAP NAS appliances used for file sharing, media storage, and remote access. The vulnerability applies to certain of these devices when Photo Station is present and the service is reachable from the internet.

How to remediate

The primary remediation is to apply the updates issued by QNAP according to the vendor instructions. CISA's required action is simply to apply those updates. After patching, reboot or restart the affected services as directed and verify that Photo Station reports the fixed version.

Once the vendor update is in place, harden the installation for this class of weakness:

If you can't patch immediately

If an immediate update is not possible, reduce the attack surface with compensating controls while you schedule the patch window.

If your data may have been exposed

Because this vulnerability has been actively used in Deadbolt ransomware campaigns, successful exploitation can lead to encryption of data stored on the NAS and potential exfiltration. If you discover evidence of compromise—unexpected file changes, ransom notes, or unexplained encryption—isolate the device, preserve forensic images, and follow your incident-response plan. As a quick external check, you can run a free exposure scan of organizational email addresses against known breach data sets to determine whether credentials or other information associated with the environment have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQNAP · Photo Station
WeaknessCWE-610
Added to CISA KEVSep 8, 2022
Federal patch deadlineSep 29, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities