CVE-2019-7194
QNAP Photo Station Path Traversal Vulnerability
Description
CVE-2019-7194 is a path traversal vulnerability in QNAP Photo Station that allows remote attackers to access or modify system files on affected QNAP NAS devices through external control of file name or path. The vulnerability enables attackers to bypass directory restrictions and reach files outside the Photo Station application boundary, potentially leading to data theft, configuration tampering, or full device compromise. CISA has added CVE-2019-7194 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 93.9% (99th percentile), this QNAP vulnerability poses an immediate and critical threat.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| qnap | photo station | < 6.0.3; < 5.7.10; < 5.4.9; < 5.2.11 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7194(US Government Resource)
Weakness Type
CWE-73: External Control of File Name or Path
CVE-2019-7194 exploits an external control of file name or path weakness in QNAP Photo Station, where the application allows user-controlled input to determine file system paths without adequate sanitization. This enables attackers to inject path traversal sequences that escape the application's intended directory scope and access arbitrary files on the QNAP NAS device's file system.
Learn more: CWE-73 — External Control of File Name or Path
Impact Analysis
CVE-2019-7194 is a critical vulnerability allowing remote attackers to bypass Photo Station's file access boundaries on QNAP NAS devices. The path traversal flaw is remotely exploitable with low attack complexity. Confidentiality is critically impacted as attackers can read any file accessible to the Photo Station process, including credentials, configuration files, and user-stored data. Integrity is also compromised through the ability to modify system files, potentially enabling persistent backdoor access. With an EPSS score of 93.9% (99th percentile), this vulnerability is nearly certain to be exploited, and CISA has confirmed it has been leveraged in ransomware campaigns targeting QNAP NAS devices, directly threatening the availability of stored data. This vulnerability is part of a family of four Photo Station flaws (CVE-2019-7192 through CVE-2019-7195) that are exploited in combination for maximum impact.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2019-7194 in the wild and documented known ransomware usage. The EPSS score of 93.9% (99th percentile) reflects near-certain exploitation probability. This vulnerability is typically exploited alongside the other QNAP Photo Station vulnerabilities (CVE-2019-7192, CVE-2019-7193, CVE-2019-7195) as part of a comprehensive attack chain against QNAP NAS devices. Ransomware groups have actively targeted internet-exposed QNAP devices using these vulnerabilities to encrypt data and demand payment, with multiple ransomware families including QLocker and eCh0raix known to target QNAP infrastructure.
Remediation
- Update QNAP Photo Station immediately to the latest patched version as directed by CISA. Consult the QNAP Security Advisory for specific patched version numbers.
- Disconnect QNAP NAS from direct internet exposure by disabling UPnP, removing port forwarding rules, and disabling myQNAPcloud remote access if not strictly necessary.
- Deploy VPN-based remote access as the sole method for accessing the NAS remotely, eliminating the ability for attackers to reach Photo Station endpoints from the internet.
- Scan the NAS file system for unauthorized modifications including unexpected files in system directories, altered configuration files, or signs of web shells that may have been placed via path traversal exploitation.
- Implement comprehensive offline backup strategy using the 3-2-1 rule with at least one backup completely disconnected from the network, as ransomware exploiting this vulnerability can encrypt all network-accessible data.
Technical Details
CVE-2019-7194 is a path traversal vulnerability in QNAP Photo Station arising from insufficient sanitization of user-controlled file path inputs. The Photo Station application processes file access requests where the file path is partially derived from user input, but fails to properly validate or canonicalize the path before performing file system operations. An attacker can inject directory traversal sequences (such as "../" or their URL-encoded equivalents) into the request, causing the application to resolve paths outside its intended document root. The QNAP NAS operating system runs Photo Station with sufficient privileges to access system-level files, meaning a successful path traversal can reach sensitive areas of the file system including /etc/shadow, /etc/config, and other configuration stores. This vulnerability works in tandem with CVE-2019-7192 (improper access control) and CVE-2019-7193 (improper input validation), forming a multi-vector attack surface against QNAP devices.
Frequently Asked Questions
Is CVE-2019-7194 being actively exploited?
Yes. CISA has confirmed active exploitation with documented ransomware usage. The EPSS score of 93.9% (99th percentile) indicates near-certain exploitation. Multiple ransomware families have targeted QNAP NAS devices through this and related Photo Station vulnerabilities.
What products are affected by CVE-2019-7194?
CVE-2019-7194 affects QNAP NAS devices running Photo Station. All Photo Station versions prior to the security fix are vulnerable. This includes the full range of QNAP NAS models across consumer and business product lines.
How do I fix CVE-2019-7194?
Update QNAP Photo Station to the latest patched version immediately. Remove the NAS from direct internet exposure, use VPN for remote access, and maintain offline backups to protect against ransomware attacks that exploit this vulnerability.
How severe is CVE-2019-7194?
CVE-2019-7194 is a critical path traversal vulnerability with an EPSS score of 93.9% in the 99th percentile and confirmed ransomware exploitation. The vulnerability enables access to arbitrary files on the NAS device and has been actively used by ransomware operators to encrypt data on QNAP devices.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.