Qnap
Qnap Photo Station: vulnerabilidades y CVE
Qnap Photo Station tiene 26 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 6 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses1
Críticas6
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-27593 | Crítica (9.1) | 88% | ⚠ Explotación activa | 8 sept 2022 | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the… |
| CVE-2019-7192 | Crítica (9.8) | 88% | ⚠ Explotación activa | 5 dic 2019 | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. |
| CVE-2019-7194 | Crítica (9.8) | 83% | ⚠ Explotación activa | 5 dic 2019 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |
| CVE-2019-7195 | Crítica (9.8) | 90% | ⚠ Explotación activa | 5 dic 2019 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-20210 | Crítica (9.8) | 0.34% | — | 11 nov 2025 | Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research. |
| CVE-2024-12923 | Baja (2) | 0.24% | — | 29 ago 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application… |
| CVE-2024-32770 | Media (5.4) | 0.37% | — | 22 nov 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already… |
| CVE-2024-32769 | Media (5.4) | 0.37% | — | 22 nov 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already… |
| CVE-2024-32768 | Media (5.4) | 0.37% | — | 22 nov 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already… |
| CVE-2024-32767 | Media (5.4) | 0.37% | — | 22 nov 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already… |
| CVE-2023-47221 | Media (4.9) | 0.45% | — | 8 mar 2024 | A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a… |
| CVE-2023-47562 | Alta (8.8) | 1.1% | — | 2 feb 2024 | An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability… |
| CVE-2023-47561 | Media (5.4) | 0.26% | — | 2 feb 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the… |
| CVE-2022-27593 | Crítica (9.1) | 88% | ⚠ Explotación activa | 8 sept 2022 | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the… |
| CVE-2021-44057 | Crítica (9.8) | 0.93% | — | 5 may 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed… |
| CVE-2021-34356 | Media (5.4) | 0.65% | — | 1 oct 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this… |
| CVE-2021-34355 | Media (5.4) | 0.65% | — | 1 oct 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this… |
| CVE-2021-34354 | Media (5.4) | 0.65% | — | 1 oct 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this… |
| CVE-2020-2502 | Media (6.1) | 0.83% | — | 17 feb 2021 | This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11… |
| CVE-2020-2491 | Media (6.1) | 0.99% | — | 10 dic 2020 | This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo… |
| CVE-2018-19956 | Media (6.1) | 0.92% | — | 2 nov 2020 | The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP… |
| CVE-2018-19955 | Media (6.1) | 0.92% | — | 2 nov 2020 | The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP… |
| CVE-2018-19954 | Media (6.1) | 0.92% | — | 2 nov 2020 | The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP… |
| CVE-2019-7195 | Crítica (9.8) | 90% | ⚠ Explotación activa | 5 dic 2019 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |
| CVE-2019-7194 | Crítica (9.8) | 83% | ⚠ Explotación activa | 5 dic 2019 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions. |
| CVE-2019-7192 | Crítica (9.8) | 88% | ⚠ Explotación activa | 5 dic 2019 | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. |
| CVE-2018-0722 | Alta (7.5) | 1.7% | — | 1 feb 2019 | Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the… |
| CVE-2018-0715 | Media (6.1) | 3.1% | — | 27 ago 2018 | Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application. |
| CVE-2017-13073 | Media (6.1) | 0.76% | — | 23 abr 2018 | Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML. |
| CVE-2013-5760 | Media (5) | 1.3% | — | 9 jun 2014 | QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.