CVE-2019-7195
QNAP Photo Station Path Traversal Vulnerability
Description
CVE-2019-7195 is a path traversal vulnerability in QNAP Photo Station that allows remote attackers to access or modify system files on affected QNAP NAS devices. The flaw stems from external control of file name or path, enabling attackers to traverse directory structures and reach files outside the intended scope of the Photo Station application. Successful exploitation can lead to unauthorized access to sensitive data stored on the NAS, modification of system configurations, or complete device compromise. CISA has added CVE-2019-7195 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 94.1% (99th percentile), this QNAP vulnerability demands immediate attention.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| qnap | photo station | < 6.0.3; < 5.7.10; < 5.4.9; < 5.2.11 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7195(US Government Resource)
Weakness Type
CWE-73: External Control of File Name or Path
CVE-2019-7195 exploits an external control of file name or path weakness in QNAP Photo Station, where user-supplied input influences the file paths used in filesystem operations without proper validation. This enables attackers to specify arbitrary paths, traversing out of the intended application directory to access, modify, or delete system-level files on the QNAP NAS device.
Learn more: CWE-73 — External Control of File Name or Path
Impact Analysis
CVE-2019-7195 is a critical vulnerability that allows remote attackers to access or modify arbitrary files on QNAP NAS devices running Photo Station. The vulnerability is remotely exploitable without requiring special conditions, and the path traversal nature means an attacker can reach any file accessible to the Photo Station process. Confidentiality is severely impacted as attackers can read sensitive files including configuration data, credentials, and user-stored data on the NAS. Integrity is compromised through the ability to modify system files, potentially installing backdoors or altering device configurations. The EPSS score of 94.1% (99th percentile) indicates near-certain exploitation activity, and CISA has confirmed that CVE-2019-7195 has been used in ransomware campaigns, making this vulnerability a direct threat to data availability as well. QNAP NAS devices often serve as primary storage for small businesses and home offices, amplifying the potential data loss impact.
Exploit Maturity
CVE-2019-7195 has reached critical exploit maturity, with CISA confirming active exploitation in the wild and known ransomware usage. The EPSS score of 94.1% (99th percentile) reflects near-certain exploitation probability. This vulnerability is part of a cluster of four related QNAP Photo Station vulnerabilities (CVE-2019-7192 through CVE-2019-7195) that are commonly exploited together to achieve complete NAS device compromise. Ransomware operators have specifically targeted QNAP NAS devices through these vulnerabilities, encrypting stored data and demanding payment for decryption keys. The widespread deployment of QNAP devices in SOHO environments, combined with the devices often being directly internet-accessible, has made this a highly effective attack vector.
Remediation
- Update QNAP Photo Station immediately to the latest patched version as required by the CISA KEV catalog. Check the QNAP Security Advisory for the specific version that addresses CVE-2019-7195.
- Remove Photo Station from internet-facing exposure by disabling UPnP port forwarding, disabling QNAP's myQNAPcloud service if not needed, and ensuring the NAS is not directly accessible from the internet.
- Implement a VPN for remote access to the QNAP NAS instead of exposing web-based management interfaces directly to the internet, as this eliminates the remote attack vector entirely.
- Enable and review QNAP access logs for indicators of path traversal attempts, including requests containing sequences like "../" or encoded variants targeting Photo Station endpoints.
- Maintain offline backups of all critical NAS data following the 3-2-1 backup rule, ensuring that ransomware attacks exploiting this vulnerability cannot destroy all copies of important files.
Technical Details
CVE-2019-7195 is a path traversal vulnerability in QNAP Photo Station caused by external control of file name or path without proper validation. The Photo Station application accepts user-supplied input that is used to construct file system paths for accessing photos and media files. However, the application fails to properly sanitize path components, allowing an attacker to inject directory traversal sequences (such as "../") or absolute paths that escape the intended media directory. When the Photo Station process resolves these manipulated paths, it accesses files outside the application's document root, potentially reaching system configuration files, credential stores, or other sensitive data on the QNAP NAS. This vulnerability is closely related to CVE-2019-7192, CVE-2019-7193, and CVE-2019-7194, which together provide a comprehensive attack surface against QNAP devices running Photo Station.
Frequently Asked Questions
Is CVE-2019-7195 being actively exploited?
Yes. CISA has confirmed active exploitation and specifically documented ransomware usage associated with CVE-2019-7195. The EPSS score of 94.1% (99th percentile) indicates near-certain exploitation. Ransomware operators have been targeting QNAP NAS devices through this and related Photo Station vulnerabilities to encrypt stored data.
What products are affected by CVE-2019-7195?
CVE-2019-7195 affects QNAP NAS devices running Photo Station. All versions prior to the security fix are vulnerable. This includes a wide range of QNAP NAS models across consumer, prosumer, and small business product lines that have Photo Station installed.
How do I fix CVE-2019-7195?
Update QNAP Photo Station to the latest patched version as identified in the QNAP Security Advisory. Additionally, remove the NAS from direct internet exposure by using VPN access instead, and maintain offline backups to mitigate ransomware risk.
How severe is CVE-2019-7195?
CVE-2019-7195 is a critical path traversal vulnerability with an EPSS score of 94.1% in the 99th percentile and confirmed ransomware exploitation. It allows remote attackers to access or modify any file on the QNAP NAS, threatening all stored data. The confirmed ransomware association makes this vulnerability an existential threat to data stored on unpatched QNAP devices.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.