PoC Index

CVE-2019-7194

KEV RANSOMWARECRITICAL 9.8EPSS 83.1%

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
83.12% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-06-08, used in ransomware campaigns
Nuclei
critical · CWE-22
Published
2019-12-05
Updated
2025-10-21

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related