CVE-2019-7194: QNAP Photo Station Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 83.1% chance of exploitation in the next 30 days.
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Affected products
- QNAP Photo Station: before 6.0.3 (fixed in 6.0.3); before 5.7.10 (fixed in 5.7.10); before 5.4.9 (fixed in 5.4.9); before 5.2.11 (fixed in 5.2.11)
Published 2019-12-05. Last modified 2026-06-17.