S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-27593 Scanner

CVE-2022-27593 scanner - Externally Controlled Reference to a Resource in Another Sphere vulnerability in QNAP Systems Inc. Photo Station

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-27593
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Photo Stationby QNAP Systems Inc.
AFFECTED< 6.1.2SAFE ✓≥ 6.1.2
Photo Stationby QNAP Systems Inc.
AFFECTED< 6.0.22SAFE ✓≥ 6.0.22
Photo Stationby QNAP Systems Inc.
AFFECTED< 6.0.22SAFE ✓≥ 6.0.22
Photo Stationby QNAP Systems Inc.
AFFECTED< 5.7.18SAFE ✓≥ 5.7.18
Updated Aug 22, 2026View on NVD →
Detail

QNAP Systems Inc. Photo Station is a popular application used by individuals and businesses to manage and store their photos and videos. Designed to work seamlessly with QNAP network-attached storage, Photo Station offers a range of features such as tagging, sharing, and editing to enhance the user experience. However, a vulnerability by the name CVE-2022-27593 has been detected in this product, which requires immediate attention.

CVE-2022-27593 is an externally controlled reference to a resource vulnerability found in Photo Station. The vulnerability is caused by improper input validation, making it possible for attackers to modify system files. As a result, attackers can exploit this vulnerability to execute arbitrary code, alter software configurations, or even compromise the entire system.

Exploitation of this vulnerability can lead to several serious consequences. For instance, attackers can delete or encrypt critical files, steal sensitive data, or use the system as a launchpad for more attacks. Additionally, they can manipulate the system to perform illegal activities, causing legal and reputational damage to the owner.

In conclusion, the vulnerability detected in QNAP Systems Inc. Photo Station is a cause for concern. However, with the right precautions, it is possible to minimize the risk of exploitation. s4e.io offers a pro feature that allows users to learn about vulnerabilities in their digital assets easily and quickly. Therefore, we encourage users to explore this platform to gain insights on how to protect their online assets and maintain digital security.

 

REFERENCES

Solution Advice

Protecting against this vulnerability is critical. Below are some of the measures that can be taken to minimize the risk:

  • Upgrade Photo Station to the latest version (QTS 5.0.1: Photo Station 6.1.2 and later, QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later, QTS 4.3.6: Photo Station 5.7.18 and later, QTS 4.3.3: Photo Station 5.4.15 and later, QTS 4.2.6: Photo Station 5.2.14 and later)
  • Use a strong and complex password to protect against brute-force attacks
  • Enable two-factor authentication to add an extra layer of security
  • Regularly update and patch the system to fix vulnerabilities and bugs
  • Limit access to the system by granting privileges only to trusted users
  • Implement network segmentation to isolate the system from the internet and other untrusted networks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-27593 scanner - Externally Controlled Reference to a Resource in Another Sphere vulnerability in QNAP Systems Inc. Photo Station | S4E