{
    "id": "CVE-2019-7195",
    "published": "2019-12-05 17:15:13",
    "last_modified": "2026-06-17 02:40:14",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-22",
    "description": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.",
    "epss_score": "0.89681",
    "epss_percentile": "0.99785",
    "kev": 1,
    "kev_due": "2022-06-22",
    "has_exploit": 0,
    "updated_at": "2026-09-26 18:25:09",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2022-06-22."
    },
    "products": [
        {
            "vendor": "qnap",
            "product": "photo_station"
        },
        {
            "vendor": "qnap",
            "product": "qts"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2019-7195",
        "date_added": "2022-06-08",
        "due_date": "2022-06-22",
        "vendor": "QNAP",
        "product": "Photo Station",
        "name": "QNAP Photo Station Path Traversal Vulnerability",
        "ransomware": 1
    },
    "exploits": [],
    "refs_list": [
        "http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html",
        "https://www.qnap.com/zh-tw/security-advisory/nas-201911-25",
        "http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html",
        "https://www.qnap.com/zh-tw/security-advisory/nas-201911-25",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7195"
    ]
}