Back

CVE-2019-7195

CRITICAL CISA KEV

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Published: Dec 5, 2019 Modified: Jun 17, 2026
CWE-22 CWE-22

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
qnap photo_station * < 6.0.3
qnap photo_station * < 5.7.10
qnap photo_station * < 5.4.9
qnap photo_station * < 5.2.11

GitHub Security Advisory GHSA-5h7g-3542-fw4q

This external control of file name or path vulnerability allows remote attackers to access or...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 89.68%

Top 0% most likely to be exploited

Threat Score 96.1 / 100

CISA Known Exploited

Date Added: 2022-06-08
Due Date: 2022-06-22
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub