EXPOSURES › CVE-2019-7195
CVE-2019-7195
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point.
QNAP Photo Station suffered a path traversal vulnerability allowing remote attackers to access or modify system files. This failure is critical for DIB orgs because it was actively exploited in the wild and linked to ransomware, demonstrating that unpatched software can become a direct ransomware vector. Organizations must rigorously patch QNAP devices and avoid relying on unpatched third-party applications.
Shame score — A known path traversal flaw was actively exploited in the wild and linked to ransomware, showing negligent patching and a severe breach of trust.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.