CVE-2018-0722: QNAP Photo Station

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.

Affected products

  • QNAP Photo Station: from 5.7.0, up to and including 5.7.2; from 5.4.0, up to and including 5.4.4; from 5.2.0, up to and including 5.2.8

Published 2019-02-01. Last modified 2026-06-17.