← Back to browse · API

CVE-2019-7195

Severity
CRITICAL
CVSS
9.8
EPSS
0.89681
Risk score
56.39
CISA KEV
Yes
PoC
No
Published
2019-12-05
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-16739, GHSA-5H7G-3542-FW4Q
Products
QNAP:Photo Station, n/a:QNAP NAS devices running Photo Station QTS 4.4.1: Photo Station before version 6.0.3, QTS 4.3.4 - QTS 4.4.0: Photo Station before version 5.7.10, QTS 4.3.0 - QTS 4.3.3: Photo Station before version 5.4.9, QTS 4.2.6: Photo Station before version 5.2.11
Sources
cisa.gov CVE-2019-7195
euvd EUVD-2019-16739

Description

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

References