← Back to browse · API

CVE-2022-27593

Severity
CRITICAL
CVSS
10.0
EPSS
0.87908
Risk score
95.77
CISA KEV
Yes
PoC
No
Published
2022-09-08
Modified
2022-09-08
First seen
2026-08-07
Aliases
EUVD-2022-32094, GHSA-C84W-PFMP-9CXG
Products
QNAP Systems Inc.:Photo Station unspecified <5.2.14, QNAP Systems Inc.:Photo Station unspecified <5.4.15, QNAP Systems Inc.:Photo Station unspecified <5.7.18, QNAP Systems Inc.:Photo Station unspecified <6.0.22, QNAP Systems Inc.:Photo Station unspecified <6.1.2, QNAP:Photo Station
Sources
euvd EUVD-2022-32094
cisa.gov CVE-2022-27593

Description

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

References