CVE-2019-7195
KEV RANSOMWARECRITICAL 9.8EPSS 89.7%
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 89.68% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-06-08, used in ransomware campaigns
- Nuclei
- critical · CWE-22
- Published
- 2019-12-05
- Updated
- 2025-10-21
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Comma…
- th3gundy/CVE-2019-7192_QNAP_Exploit87★ · 2020-05-24