Skip to content
COOEY

FAIL › dossier

Photo Station

PRODUCT

· dossier confidence 80%

QNAP Photo Station has a critical security posture with multiple unpatched vulnerabilities exploited in ransomware campaigns, including CVE-2022-27593 RCE and path traversal flaws.

PROFILE
CategoryProductWhat they doQNAP Photo Station is a network-attached storage (NAS) device designed for photo management and backup.
SECURITY POSTURE

Critical security track record with multiple unpatched vulnerabilities exploited in ransomware campaigns.

Notable failures
  • CVE-2022-27593 RCE exploited in Deadbolt ransomware
  • CVE-2019-7194 path traversal ransomware entry point
  • CVE-2019-7195 path traversal ransomware entry point
  • CVE-2019-7192 RCE bypass authentication
Patterns: Repeated critical RCE and path traversal vulnerabilities; Vulnerabilities serving as ransomware entry points
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2022-09-08 CVE-2022-27593 critical QNAP Photo Station's externally controlled reference vulnerability allowed attackers to modify system files and was actively exploited in a Deadbolt ransomware campaign.
2022-06-08 CVE-2019-7194 critical QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point.
2022-06-08 CVE-2019-7195 critical QNAP Photo Station's path traversal flaw let attackers read/modify system files, serving as a ransomware entry point.
2022-06-08 CVE-2019-7192 critical QNAP Photo Station's improper access control flaw allowed remote attackers to bypass authentication and gain unauthorized system access.
Open questions: Current patch status of CVE-2022-27593 · QNAP Photo Station CMMC compliance status
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:45:37.790046+00:00