CVE-2017-20210: QNAP Photo Station

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

Affected products

  • QNAP Photo Station: version 5.2.7 only; version 5.4.1 only

Published 2025-11-11. Last modified 2026-06-17.