CVE-2022-27593: QNAP Photo Station externally controlled reference, exploited by DeadBolt ransomware
The short version: CVE-2022-27593 is an externally controlled reference flaw in QNAP Photo Station on internet-facing NAS devices — it let attackers modify system files, and it was the vector behind a DeadBolt ransomware campaign against exposed QNAP boxes in 2022. It's in CISA's KEV catalog. Photo Station isn't installed by default, so exposure is specific — but where it's present and reachable, this is patch-and-verify. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | Moderate — the vector for real ransomware against exposed NAS (see below) |
| CVSS v3.1 (NVD) | 9.1 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| EPSS | ~87.91% · 99.75th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediate by 2022-09-29 |
| Known exploited? | Yes — used in a DeadBolt ransomware campaign |
| Vulnerability type | CWE-610 externally controlled reference to a resource → modification of system files |
| Requires authenticated session? | No — pre-authentication |
| Affected | QNAP NAS running Photo Station (not installed by default) — see fixed versions below |
| Fixed in | Photo Station: QTS 5.0.1 → 6.1.2+ · QTS 5.0.0 / 4.5.x → 6.0.22+ · QTS 4.3.6 → 5.7.18+ · QTS 4.3.3 → 5.4.15+ · QTS 4.2.6 → 5.2.14+ |
What you need to know
Photo Station is an optional QNAP app for browsing photos on a NAS. CVE-2022-27593 is an externally controlled reference to a resource flaw: an attacker can supply a reference that resolves to a resource outside the intended control sphere, allowing modification of system files on the device — with no authentication.
- How they find it — internet-wide scanning surfaces exposed QNAP NAS devices; the vulnerability requires the Photo Station app to be installed.
- How they use it — unauthenticated manipulation of system files on the reachable device.
- What it leads to — in 2022, this was the entry point for a DeadBolt ransomware campaign that encrypted exposed QNAP NAS devices.
Note: BreachBits' internal threat definition for this item was tagged as not being in CISA KEV; verification against the CISA KEV catalog shows it is listed (remediation due 2022-09-29). We've reflected the authoritative status here.
How serious we see it
Moderate — grounded in what actually happened.
NVD scores it 9.1 (integrity and availability, no confidentiality). We rate it High: it's unauthenticated, it was the real-world vector for a ransomware campaign against internet-facing NAS, and it's KEV-listed. The reason it isn't a blanket Critical is exposure scope — Photo Station isn't installed by default, so many QNAP owners simply don't run the affected component. Where it is installed and reachable, treat it as urgent. The bounded, reassuring part: fixed Photo Station versions are published, and the strongest control — keeping the NAS off the public internet — is entirely in your hands.
Recommendations
Straight from QNAP's advisory (QSA-22-24) and CISA:
- Update Photo Station and QTS now. Move to a fixed Photo Station version for your QTS release (see the table above), and keep QTS current.
- Get the NAS off the internet. Disable router port forwarding and use QNAP's secure remote-access (myQNAPcloud) instead of direct exposure.
- Harden accounts and back up. Use strong, unique passwords, and take snapshots / offline backups so ransomware can't leave you without recovery.
- If compromised, respond. Isolate the device, preserve evidence, and restore from clean backups rather than paying.
- Confirm your exposure first. Verify whether any QNAP NAS with Photo Station is reachable from the internet.
How BreachRisk sees it
BreachRisk discovers internet-facing QNAP NAS devices from little more than your domain, fingerprints the product and exposed applications, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one so it rises to the top of your results.
That continuous, outside-in view is the point: a NAS someone stood up for convenience and forgot — exactly the kind of device ransomware crews hunt — surfaces as a ranked, KEV-flagged finding before it becomes an incident.