ZeroHour

CVE-2019-7192

KEV ransomware PoC large

Unauthenticated Improper Access Control in QNAP Photo Station

CISA: QNAP Photo Station Improper Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2019-7192 is a critical improper access control flaw (CWE-863) in QNAP Photo Station, the web-based photo application that runs on QNAP QTS NAS devices. Because the flaw is reachable over the network without credentials or user interaction (CVSS 3.1 9.8), remote attackers can gain unauthorized access to vulnerable systems. A public proof of concept demonstrates chaining the bug into remote command execution on Photo Station 6.0.3 under QTS, giving attackers the ability to execute commands on the NAS. Any QNAP NAS running an outdated Photo Station, particularly when its web interface is exposed to untrusted networks, is affected. Exploitation is confirmed in the wild: CISA added it to the KEV on 2022-06-08 with known ransomware use, and EPSS assigns a 88.2% probability of exploitation in the next 30 days (top percentile).

What to do: Update Photo Station to the latest version per QNAP's security advisory, and verify the installed Photo Station version on every QTS NAS. Where updating is not immediately possible, disable Photo Station or restrict its web endpoints to trusted networks, and check devices for signs of compromise given the known ransomware exploitation.

Affected
QNAP Photo Station (runs on QTS NAS)Photo Station 6.0.3 demonstrated vulnerable in the public PoC; QNAP advises updating Photo Station to the latest versions per its security advisory
Estimated exposure
largetens of thousands of internet-exposed QNAP NAS running Photo Station (public scan counts) — Photo Station ships with QNAP's widely deployed QTS NAS platform, and public internet scans have repeatedly shown tens of thousands of exposed Photo Station instances, with the overall QNAP installed base in the millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CISA Known Exploited Vulnerability
Affected
QNAP Photo Station
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
photo station
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news