Vulnerability record · CVE-2019-7192 · published 5 December 2019
CVE-2019-7192: QNAP Photo Station improper access control allows unauthenticated remote access
Qnap · Photo Station
QNAP Photo Station contains an improper access control flaw (CWE-863) that lets remote attackers gain unauthorized access to the system. It is rated CVSS 3.1 9.8 critical and is listed in CISA KEV with known ransomware campaign use, so it is a high-value target for defenders.
Description
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated remote access control flaw, listed in CISA KEV with known ransomware use and very high EPSS.
What it is
QNAP Photo Station contains an improper access control flaw (CWE-863) that lets remote attackers gain unauthorized access to the system. It is rated CVSS 3.1 9.8 critical and is listed in CISA KEV with known ransomware campaign use, so it is a high-value target for defenders.
Impact
An unauthenticated remote attacker can bypass authorization and gain access to the system, with the potential for full compromise of confidentiality, integrity and availability given the CVSS scope.
Attack surface
Reachable over the network via the Photo Station service with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
CISA KEV lists it as exploited in the wild and associated with known ransomware campaigns, and EPSS is 0.88213 (99.76th percentile); a public exploit reference exists on Packet Storm.
What to do
- Update QNAP Photo Station to the latest version per the vendor security advisory NAS-201911-25.
- If Photo Station is not needed, disable or uninstall it to remove the exposure.
- Restrict network access to Photo Station and QNAP management interfaces to trusted networks or VPN only.
- Monitor QNAP advisories and apply QTS firmware updates that address related issues.
- Verify no unauthorized accounts or persistence were created on affected NAS devices.
Detection
- Review Photo Station and QTS web access logs for anomalous or unauthenticated requests around the time of suspected activity.
- Hunt for unexpected account creation, privilege changes, or new administrative users on QNAP NAS systems.
- Monitor for known exploitation artifacts and post-exploitation behavior tied to ransomware on NAS devices.
- Alert on external access to Photo Station endpoints from untrusted IP addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-7192 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "QNAP Photo Station Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 | Vendor Advisory |
| http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.qnap.com/zh-tw/security-advisory/nas-201911-25 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7192 | US Government Resource |
Track CVE-2019-7192 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-7192), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.