CVE-2019-7194

CRITICAL(9.8)KEVRansomwareLikely Exploited

QNAP Photo Station Path Traversal Vulnerability

Description

CVE-2019-7194 is a path traversal vulnerability in QNAP Photo Station that allows remote attackers to access or modify system files on affected QNAP NAS devices through external control of file name or path. The vulnerability enables attackers to bypass directory restrictions and reach files outside the Photo Station application boundary, potentially leading to data theft, configuration tampering, or full device compromise. CISA has added CVE-2019-7194 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 93.9% (99th percentile), this QNAP vulnerability poses an immediate and critical threat.

KEV Information

Vendor
QNAP
Product
Photo Station
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
qnapphoto station< 6.0.3; < 5.7.10; < 5.4.9; < 5.2.11

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-73: External Control of File Name or Path

CVE-2019-7194 exploits an external control of file name or path weakness in QNAP Photo Station, where the application allows user-controlled input to determine file system paths without adequate sanitization. This enables attackers to inject path traversal sequences that escape the application's intended directory scope and access arbitrary files on the QNAP NAS device's file system.

Learn more: CWE-73 — External Control of File Name or Path

Impact Analysis

CVE-2019-7194 is a critical vulnerability allowing remote attackers to bypass Photo Station's file access boundaries on QNAP NAS devices. The path traversal flaw is remotely exploitable with low attack complexity. Confidentiality is critically impacted as attackers can read any file accessible to the Photo Station process, including credentials, configuration files, and user-stored data. Integrity is also compromised through the ability to modify system files, potentially enabling persistent backdoor access. With an EPSS score of 93.9% (99th percentile), this vulnerability is nearly certain to be exploited, and CISA has confirmed it has been leveraged in ransomware campaigns targeting QNAP NAS devices, directly threatening the availability of stored data. This vulnerability is part of a family of four Photo Station flaws (CVE-2019-7192 through CVE-2019-7195) that are exploited in combination for maximum impact.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2019-7194 in the wild and documented known ransomware usage. The EPSS score of 93.9% (99th percentile) reflects near-certain exploitation probability. This vulnerability is typically exploited alongside the other QNAP Photo Station vulnerabilities (CVE-2019-7192, CVE-2019-7193, CVE-2019-7195) as part of a comprehensive attack chain against QNAP NAS devices. Ransomware groups have actively targeted internet-exposed QNAP devices using these vulnerabilities to encrypt data and demand payment, with multiple ransomware families including QLocker and eCh0raix known to target QNAP infrastructure.

Remediation

  1. Update QNAP Photo Station immediately to the latest patched version as directed by CISA. Consult the QNAP Security Advisory for specific patched version numbers.
  2. Disconnect QNAP NAS from direct internet exposure by disabling UPnP, removing port forwarding rules, and disabling myQNAPcloud remote access if not strictly necessary.
  3. Deploy VPN-based remote access as the sole method for accessing the NAS remotely, eliminating the ability for attackers to reach Photo Station endpoints from the internet.
  4. Scan the NAS file system for unauthorized modifications including unexpected files in system directories, altered configuration files, or signs of web shells that may have been placed via path traversal exploitation.
  5. Implement comprehensive offline backup strategy using the 3-2-1 rule with at least one backup completely disconnected from the network, as ransomware exploiting this vulnerability can encrypt all network-accessible data.

Technical Details

CVE-2019-7194 is a path traversal vulnerability in QNAP Photo Station arising from insufficient sanitization of user-controlled file path inputs. The Photo Station application processes file access requests where the file path is partially derived from user input, but fails to properly validate or canonicalize the path before performing file system operations. An attacker can inject directory traversal sequences (such as "../" or their URL-encoded equivalents) into the request, causing the application to resolve paths outside its intended document root. The QNAP NAS operating system runs Photo Station with sufficient privileges to access system-level files, meaning a successful path traversal can reach sensitive areas of the file system including /etc/shadow, /etc/config, and other configuration stores. This vulnerability works in tandem with CVE-2019-7192 (improper access control) and CVE-2019-7193 (improper input validation), forming a multi-vector attack surface against QNAP devices.

Frequently Asked Questions

Is CVE-2019-7194 being actively exploited?

Yes. CISA has confirmed active exploitation with documented ransomware usage. The EPSS score of 93.9% (99th percentile) indicates near-certain exploitation. Multiple ransomware families have targeted QNAP NAS devices through this and related Photo Station vulnerabilities.

What products are affected by CVE-2019-7194?

CVE-2019-7194 affects QNAP NAS devices running Photo Station. All Photo Station versions prior to the security fix are vulnerable. This includes the full range of QNAP NAS models across consumer and business product lines.

How do I fix CVE-2019-7194?

Update QNAP Photo Station to the latest patched version immediately. Remove the NAS from direct internet exposure, use VPN for remote access, and maintain offline backups to protect against ransomware attacks that exploit this vulnerability.

How severe is CVE-2019-7194?

CVE-2019-7194 is a critical path traversal vulnerability with an EPSS score of 93.9% in the 99th percentile and confirmed ransomware exploitation. The vulnerability enables access to arbitrary files on the NAS device and has been actively used by ransomware operators to encrypt data on QNAP devices.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score83.12%
EPSS Percentile99.7%

Dates

PublishedDecember 5, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.