Loading vulnerability details…
CVSS v3.1
9.8
EPSS
88.21%
Published
Dec 5, 2019
Modified
Oct 27, 2025
CISA Known Exploited Vulnerability
Added: 2022-06-08 · Due: 2022-06-22
Apply updates per vendor instructions.
Public PoC / Exploit (4)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (8)
References (5)