Skip to content
COOEY

EXPOSURES › CVE-2019-7194

CVE-2019-7194

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-7194 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatched

QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point.

QNAP Photo Station suffered a path traversal vulnerability allowing remote attackers to access or modify system files. This failure is critical for DIB orgs because it directly enables ransomware deployment and violates CMMC/NIST 800-171 controls around patch management and supply-chain risk. Organizations must verify QNAP firmware versions and isolate affected devices until patched.

Shame score — A known, actively exploited path traversal flaw linked to ransomware that vendors failed to patch promptly, demonstrating severe negligence and supply-chain risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.