First published: Thu Dec 05 2019(Updated: )
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <6.0.3 | |
QNAP QTS | =4.4.1 | |
QNAP Photo Station | <5.7.10 | |
QNAP QTS | >=4.3.4<=4.4.0 | |
QNAP Photo Station | <5.4.9 | |
QNAP QTS | >=4.3.0<=4.3.3 | |
QNAP Photo Station | <5.2.11 | |
QNAP QTS | =4.2.6 | |
QNAP Photo Station | ||
All of | ||
QNAP Photo Station | <6.0.3 | |
QNAP QTS | =4.4.1 | |
All of | ||
QNAP Photo Station | <5.7.10 | |
QNAP QTS | >=4.3.4<=4.4.0 | |
All of | ||
QNAP Photo Station | <5.4.9 | |
QNAP QTS | >=4.3.0<=4.3.3 | |
All of | ||
QNAP Photo Station | <5.2.11 | |
QNAP QTS | =4.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7194 is a vulnerability that allows remote attackers to access or modify system files in QNAP Photo Station.
CVE-2019-7194 has a severity rating of 9.8 (Critical).
QNAP Photo Station versions up to 6.0.3 are affected.
To fix CVE-2019-7194, it is recommended to update Photo Station to the latest version provided by QNAP.
More information about CVE-2019-7194 can be found at the following references: [link1](http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html), [link2](https://www.qnap.com/zh-tw/security-advisory/nas-201911-25).