CVE-2019-7192
KEV ransomware PoC largeUnauthenticated Improper Access Control in QNAP Photo Station
CISA: QNAP Photo Station Improper Access Control Vulnerability
CVE-2019-7192 is a critical improper access control flaw (CWE-863) in QNAP Photo Station, the web-based photo application that runs on QNAP QTS NAS devices. Because the flaw is reachable over the network without credentials or user interaction (CVSS 3.1 9.8), remote attackers can gain unauthorized access to vulnerable systems. A public proof of concept demonstrates chaining the bug into remote command execution on Photo Station 6.0.3 under QTS, giving attackers the ability to execute commands on the NAS. Any QNAP NAS running an outdated Photo Station, particularly when its web interface is exposed to untrusted networks, is affected. Exploitation is confirmed in the wild: CISA added it to the KEV on 2022-06-08 with known ransomware use, and EPSS assigns a 88.2% probability of exploitation in the next 30 days (top percentile).
What to do: Update Photo Station to the latest version per QNAP's security advisory, and verify the installed Photo Station version on every QTS NAS. Where updating is not immediately possible, disable Photo Station or restrict its web endpoints to trusted networks, and check devices for signs of compromise given the known ransomware exploitation.
| QNAP Photo Station (runs on QTS NAS) | Photo Station 6.0.3 demonstrated vulnerable in the public PoC; QNAP advises updating Photo Station to the latest versions per its security advisory |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
- Affected
- QNAP Photo Station
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- photo station
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H