← KEV catalog
CISA known exploited vulnerability

CVE-2019-7194

QNAP Photo Station Path Traversal Vulnerability

SOURCE FACT

QNAP · Photo Station

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2019-7194

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?