CVE-2019-7195

CRITICAL(9.8)KEVRansomwareLikely Exploited

QNAP Photo Station Path Traversal Vulnerability

Description

CVE-2019-7195 is a path traversal vulnerability in QNAP Photo Station that allows remote attackers to access or modify system files on affected QNAP NAS devices. The flaw stems from external control of file name or path, enabling attackers to traverse directory structures and reach files outside the intended scope of the Photo Station application. Successful exploitation can lead to unauthorized access to sensitive data stored on the NAS, modification of system configurations, or complete device compromise. CISA has added CVE-2019-7195 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 94.1% (99th percentile), this QNAP vulnerability demands immediate attention.

KEV Information

Vendor
QNAP
Product
Photo Station
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
qnapphoto station< 6.0.3; < 5.7.10; < 5.4.9; < 5.2.11

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-73: External Control of File Name or Path

CVE-2019-7195 exploits an external control of file name or path weakness in QNAP Photo Station, where user-supplied input influences the file paths used in filesystem operations without proper validation. This enables attackers to specify arbitrary paths, traversing out of the intended application directory to access, modify, or delete system-level files on the QNAP NAS device.

Learn more: CWE-73 — External Control of File Name or Path

Impact Analysis

CVE-2019-7195 is a critical vulnerability that allows remote attackers to access or modify arbitrary files on QNAP NAS devices running Photo Station. The vulnerability is remotely exploitable without requiring special conditions, and the path traversal nature means an attacker can reach any file accessible to the Photo Station process. Confidentiality is severely impacted as attackers can read sensitive files including configuration data, credentials, and user-stored data on the NAS. Integrity is compromised through the ability to modify system files, potentially installing backdoors or altering device configurations. The EPSS score of 94.1% (99th percentile) indicates near-certain exploitation activity, and CISA has confirmed that CVE-2019-7195 has been used in ransomware campaigns, making this vulnerability a direct threat to data availability as well. QNAP NAS devices often serve as primary storage for small businesses and home offices, amplifying the potential data loss impact.

Exploit Maturity

CVE-2019-7195 has reached critical exploit maturity, with CISA confirming active exploitation in the wild and known ransomware usage. The EPSS score of 94.1% (99th percentile) reflects near-certain exploitation probability. This vulnerability is part of a cluster of four related QNAP Photo Station vulnerabilities (CVE-2019-7192 through CVE-2019-7195) that are commonly exploited together to achieve complete NAS device compromise. Ransomware operators have specifically targeted QNAP NAS devices through these vulnerabilities, encrypting stored data and demanding payment for decryption keys. The widespread deployment of QNAP devices in SOHO environments, combined with the devices often being directly internet-accessible, has made this a highly effective attack vector.

Remediation

  1. Update QNAP Photo Station immediately to the latest patched version as required by the CISA KEV catalog. Check the QNAP Security Advisory for the specific version that addresses CVE-2019-7195.
  2. Remove Photo Station from internet-facing exposure by disabling UPnP port forwarding, disabling QNAP's myQNAPcloud service if not needed, and ensuring the NAS is not directly accessible from the internet.
  3. Implement a VPN for remote access to the QNAP NAS instead of exposing web-based management interfaces directly to the internet, as this eliminates the remote attack vector entirely.
  4. Enable and review QNAP access logs for indicators of path traversal attempts, including requests containing sequences like "../" or encoded variants targeting Photo Station endpoints.
  5. Maintain offline backups of all critical NAS data following the 3-2-1 backup rule, ensuring that ransomware attacks exploiting this vulnerability cannot destroy all copies of important files.

Technical Details

CVE-2019-7195 is a path traversal vulnerability in QNAP Photo Station caused by external control of file name or path without proper validation. The Photo Station application accepts user-supplied input that is used to construct file system paths for accessing photos and media files. However, the application fails to properly sanitize path components, allowing an attacker to inject directory traversal sequences (such as "../") or absolute paths that escape the intended media directory. When the Photo Station process resolves these manipulated paths, it accesses files outside the application's document root, potentially reaching system configuration files, credential stores, or other sensitive data on the QNAP NAS. This vulnerability is closely related to CVE-2019-7192, CVE-2019-7193, and CVE-2019-7194, which together provide a comprehensive attack surface against QNAP devices running Photo Station.

Frequently Asked Questions

Is CVE-2019-7195 being actively exploited?

Yes. CISA has confirmed active exploitation and specifically documented ransomware usage associated with CVE-2019-7195. The EPSS score of 94.1% (99th percentile) indicates near-certain exploitation. Ransomware operators have been targeting QNAP NAS devices through this and related Photo Station vulnerabilities to encrypt stored data.

What products are affected by CVE-2019-7195?

CVE-2019-7195 affects QNAP NAS devices running Photo Station. All versions prior to the security fix are vulnerable. This includes a wide range of QNAP NAS models across consumer, prosumer, and small business product lines that have Photo Station installed.

How do I fix CVE-2019-7195?

Update QNAP Photo Station to the latest patched version as identified in the QNAP Security Advisory. Additionally, remove the NAS from direct internet exposure by using VPN access instead, and maintain offline backups to mitigate ransomware risk.

How severe is CVE-2019-7195?

CVE-2019-7195 is a critical path traversal vulnerability with an EPSS score of 94.1% in the 99th percentile and confirmed ransomware exploitation. It allows remote attackers to access or modify any file on the QNAP NAS, threatening all stored data. The confirmed ransomware association makes this vulnerability an existential threat to data stored on unpatched QNAP devices.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score89.68%
EPSS Percentile99.8%

Dates

PublishedDecember 5, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.