CVE-2022-27593
Description
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
Summary dbcve.org
An externally controlled reference to a resource vulnerability in QNAP Photo Station allows attackers to modify system files via path traversal or improper resource handling. This critical flaw in the photo management application enables unauthorized file system access on affected NAS devices.
Mitigation
Update Photo Station to the fixed versions specified for your QTS version (6.1.2 for QTS 5.0.1, 6.0.22 for QTS 5.0.0/4.5.x, 5.7.18 for QTS 4.3.6, 5.4.15 for QTS 4.3.3, or 5.2.14 for QTS 4.2.6). Review QNAP advisory for complete patching instructions.