Showing 8 vulnerabilities on this page for Photo Station

Signals CISA KEV Ransomware Nuclei
QNAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Photo Station

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

CWE-200Nov 11, 2025
CVSS9.8v3.1EPSS0.345%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

DeadBolt Ransomware

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CWE-610Sep 8, 20221 related artifact
CVSS10.0v3.1EPSS87.9%PoCs0SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

QNAP Photo Station Path Traversal Vulnerability

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CWE-22CWE-610Dec 5, 20191 related artifact
CVSS9.8v3.1EPSS89.7%PoCs3SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

QNAP Photo Station Path Traversal Vulnerability

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

CWE-22CWE-610Dec 5, 20191 related artifact
CVSS9.8v3.1EPSS83.1%PoCs1SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

QNAP Photo Station Improper Access Control Vulnerability

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CWE-269CWE-863Dec 5, 20191 related artifact
CVSS9.8v3.1EPSS88.2%PoCs3SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.

CWE-22Feb 1, 2019
CVSS7.5v3.0EPSS1.74%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

QNAP Photo Station 5.7.0 - Cross-Site Scripting

Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.

CWE-79Aug 27, 2018
CVSS6.1v3.0EPSS3.12%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

CWE-79Apr 23, 2018
CVSS6.1v3.0EPSS0.772%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX