CVE-2019-7194: QNAP Photo Station Path Traversal Vulnerability
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Other sources
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7194?
CVE-2019-7194 is a vulnerability that allows remote attackers to access or modify system files in QNAP Photo Station.
How severe is CVE-2019-7194?
CVE-2019-7194 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2019-7194?
QNAP Photo Station versions up to 6.0.3 are affected.
How can I fix CVE-2019-7194?
To fix CVE-2019-7194, it is recommended to update Photo Station to the latest version provided by QNAP.
Where can I find more information about CVE-2019-7194?
More information about CVE-2019-7194 can be found at the following references: [link1](http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html), [link2](https://www.qnap.com/zh-tw/security-advisory/nas-201911-25).