>> All posts

CVE-2022-27593: QNAP Photo Station externally controlled reference, exploited by DeadBolt ransomware

The short version: CVE-2022-27593 is an externally controlled reference flaw in QNAP Photo Station on internet-facing NAS devices — it let attackers modify system files, and it was the vector behind a DeadBolt ransomware campaign against exposed QNAP boxes in 2022. It's in CISA's KEV catalog. Photo Station isn't installed by default, so exposure is specific — but where it's present and reachable, this is patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeModerate — the vector for real ransomware against exposed NAS (see below)
CVSS v3.1 (NVD)9.1 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS~87.91% · 99.75th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2022-09-29
Known exploited?Yes — used in a DeadBolt ransomware campaign
Vulnerability typeCWE-610 externally controlled reference to a resource → modification of system files
Requires authenticated session?No — pre-authentication
AffectedQNAP NAS running Photo Station (not installed by default) — see fixed versions below
Fixed inPhoto Station: QTS 5.0.1 → 6.1.2+ · QTS 5.0.0 / 4.5.x → 6.0.22+ · QTS 4.3.6 → 5.7.18+ · QTS 4.3.3 → 5.4.15+ · QTS 4.2.6 → 5.2.14+

What you need to know

Photo Station is an optional QNAP app for browsing photos on a NAS. CVE-2022-27593 is an externally controlled reference to a resource flaw: an attacker can supply a reference that resolves to a resource outside the intended control sphere, allowing modification of system files on the device — with no authentication.

  • How they find it — internet-wide scanning surfaces exposed QNAP NAS devices; the vulnerability requires the Photo Station app to be installed.
  • How they use it — unauthenticated manipulation of system files on the reachable device.
  • What it leads to — in 2022, this was the entry point for a DeadBolt ransomware campaign that encrypted exposed QNAP NAS devices.

Note: BreachBits' internal threat definition for this item was tagged as not being in CISA KEV; verification against the CISA KEV catalog shows it is listed (remediation due 2022-09-29). We've reflected the authoritative status here.

How serious we see it

Moderate — grounded in what actually happened.

NVD scores it 9.1 (integrity and availability, no confidentiality). We rate it High: it's unauthenticated, it was the real-world vector for a ransomware campaign against internet-facing NAS, and it's KEV-listed. The reason it isn't a blanket Critical is exposure scope — Photo Station isn't installed by default, so many QNAP owners simply don't run the affected component. Where it is installed and reachable, treat it as urgent. The bounded, reassuring part: fixed Photo Station versions are published, and the strongest control — keeping the NAS off the public internet — is entirely in your hands.

Recommendations

Straight from QNAP's advisory (QSA-22-24) and CISA:

  1. Update Photo Station and QTS now. Move to a fixed Photo Station version for your QTS release (see the table above), and keep QTS current.
  2. Get the NAS off the internet. Disable router port forwarding and use QNAP's secure remote-access (myQNAPcloud) instead of direct exposure.
  3. Harden accounts and back up. Use strong, unique passwords, and take snapshots / offline backups so ransomware can't leave you without recovery.
  4. If compromised, respond. Isolate the device, preserve evidence, and restore from clean backups rather than paying.
  5. Confirm your exposure first. Verify whether any QNAP NAS with Photo Station is reachable from the internet.

How BreachRisk sees it

BreachRisk discovers internet-facing QNAP NAS devices from little more than your domain, fingerprints the product and exposed applications, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one so it rises to the top of your results.

That continuous, outside-in view is the point: a NAS someone stood up for convenience and forgot — exactly the kind of device ransomware crews hunt — surfaces as a ranked, KEV-flagged finding before it becomes an incident.

References

See your cyber risk, proven.