Vulnerability
QNAP Photo Station Path Traversal Vulnerability
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
Apply updates per vendor instructions.
CISA description: “QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HStatistically about to be weaponized — top-tier triage urgency.
No VEX statements published for CVE-2019-7194. Vendors publish VEX (Vulnerability Exploitability eXchange) to assert per-product whether a CVE is actually exploitable in their distribution.
Active exploitation with total impact on essential/support systems