A AegiFlow
UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2022-27593

QNAP Photo Station Externally Controlled Reference Vulnerability

Published
2022-09-08
Modified
2026-07-31
Sources
cisa-kev

Summary

Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacker to modify system files. This vulnerability was observed being utilized in a Deadbolt ransomware campaign.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.