CVE-2022-27593—QNAP Photo Station Externally Controlled Reference Vulnerability
PUBLISHEDvulnerability record
2022-09-08 · last modified June 21, 2025
Metadata
Vulnerability Name
QNAP Photo Station Externally Controlled Reference Vulnerability
Description
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.