CVE-2019-7195: QNAP Photo Station Path Traversal Vulnerability
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Other sources
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7195?
CVE-2019-7195 is the QNAP Photo Station Path Traversal Vulnerability, which allows remote attackers to access or modify system files.
How can I fix CVE-2019-7195?
To fix CVE-2019-7195, QNAP recommends updating Photo Station to their latest version.
What is the severity of CVE-2019-7195?
The severity of CVE-2019-7195 is critical, with a CVSS score of 9.8.
Which software versions are affected by CVE-2019-7195?
QNAP Photo Station versions up to 6.0.3 are affected by CVE-2019-7195.
Are QNAP QTS versions vulnerable to CVE-2019-7195?
No, QNAP QTS versions 4.4.1 and above are not vulnerable to CVE-2019-7195.