June 8, 2022 · Applied Cybernetics Group
CVE-2019-7195 — QNAP Photo Station
known ransomware use
QNAP Photo Station Path Traversal Vulnerability
- Added to KEV
2022-06-08- Federal due date
2022-06-22- Vendor
- QNAP
- Product
- Photo Station
- EPSS
- 99.9th percentile (score 0.941, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-7195
CISA short description
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
Required action
Apply updates per vendor instructions.