CVE-2019-7192

CRITICAL(9.8)KEVRansomwareLikely Exploited

QNAP Photo Station Improper Access Control Vulnerability

Description

CVE-2019-7192 is an improper access control vulnerability in QNAP Photo Station that allows remote attackers to gain unauthorized access to QNAP NAS devices. The flaw enables attackers to bypass authentication and access control mechanisms, reaching system resources without valid credentials. Successful exploitation of this QNAP vulnerability can lead to unauthorized data access, configuration changes, and serve as an entry point for further attacks. CISA has added CVE-2019-7192 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 94.3% (99th percentile), this represents one of the most actively exploited QNAP vulnerabilities.

KEV Information

Vendor
QNAP
Product
Photo Station
Date Added
June 8, 2022
Due Date
June 22, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
qnapphoto station< 6.0.3; < 5.7.10; < 5.4.9; < 5.2.11

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-284: Improper Access Control

CVE-2019-7192 exploits an improper access control weakness in QNAP Photo Station, where the application fails to properly restrict access to resources from unauthorized actors. This allows remote attackers to bypass authentication requirements and access system-level functionality on the QNAP NAS device without providing valid credentials, undermining the fundamental security boundary of the device.

Learn more: CWE-284 — Improper Access Control

Impact Analysis

CVE-2019-7192 is a critical vulnerability in QNAP Photo Station that allows remote attackers to bypass access controls and gain unauthorized access to the NAS device. The vulnerability requires no authentication and has low attack complexity, making it trivially exploitable by any attacker with network access. Confidentiality is critically impacted as unauthorized access enables reading sensitive files, credentials, and all data stored on the NAS. Integrity is compromised through the ability to modify system settings and stored data. Availability is directly threatened as CISA has confirmed ransomware usage associated with this vulnerability. The EPSS score of 94.3% (99th percentile) indicates near-certain exploitation activity. CVE-2019-7192 is the foundational vulnerability in the QNAP Photo Station attack chain (CVE-2019-7192 through CVE-2019-7195), providing the initial access that enables exploitation of the companion path traversal and input validation vulnerabilities.

Exploit Maturity

CVE-2019-7192 has reached maximum exploit maturity with CISA confirming active exploitation and known ransomware usage. The EPSS score of 94.3% (99th percentile) — the highest in the QNAP vulnerability cluster — reflects near-certain exploitation probability. This vulnerability serves as the initial access vector in the chain of four QNAP Photo Station vulnerabilities (CVE-2019-7192 through CVE-2019-7195) that ransomware operators have systematically exploited. Multiple ransomware families have been observed targeting internet-exposed QNAP NAS devices, using this improper access control vulnerability to establish an initial foothold before leveraging the path traversal and code injection vulnerabilities for full device compromise and data encryption.

Remediation

  1. Update QNAP Photo Station immediately to the latest patched version as required by the CISA KEV catalog. Consult the QNAP Security Advisory for specific version details.
  2. Remove QNAP NAS from direct internet exposure immediately — this is the most critical mitigation. Disable UPnP, remove port forwarding rules, and disable myQNAPcloud if not strictly required.
  3. Implement VPN-only remote access to the QNAP NAS, ensuring that no QNAP web interfaces are directly reachable from the public internet.
  4. Review and strengthen access controls on the NAS, including disabling unnecessary Photo Station accounts, enforcing strong passwords, and enabling two-factor authentication where available.
  5. Implement and verify a 3-2-1 backup strategy with at least one completely offline backup copy, given the confirmed ransomware threat associated with this vulnerability cluster.

Technical Details

CVE-2019-7192 is an improper access control vulnerability in QNAP Photo Station that allows remote attackers to bypass the application's authentication and authorization mechanisms. The Photo Station application fails to properly verify that incoming requests originate from authenticated and authorized users, allowing unauthenticated attackers to access protected resources and functionality. The access control bypass provides an initial foothold that attackers use in combination with the path traversal vulnerabilities (CVE-2019-7194, CVE-2019-7195) and input validation flaw (CVE-2019-7193) to achieve comprehensive NAS compromise. The vulnerability is exploitable through standard HTTP requests to the Photo Station web interface, requiring no special tools or sophisticated exploitation techniques. Given that QNAP NAS devices often store critical business data and personal files, and are frequently exposed to the internet through automatic port forwarding features, the impact of this access control bypass extends to the security of all data on the device.

Frequently Asked Questions

Is CVE-2019-7192 being actively exploited?

Yes. CISA has confirmed active exploitation with documented ransomware usage. The EPSS score of 94.3% (99th percentile) indicates near-certain exploitation. This is the primary access control bypass in the QNAP vulnerability cluster actively targeted by ransomware operators.

What products are affected by CVE-2019-7192?

CVE-2019-7192 affects QNAP NAS devices running Photo Station. All versions prior to the security fix are vulnerable. The full range of QNAP NAS models is affected regardless of hardware specifications.

How do I fix CVE-2019-7192?

Update QNAP Photo Station to the latest patched version immediately. As a critical first step, remove the NAS from direct internet exposure and implement VPN-only remote access. Maintain verified offline backups to protect against ransomware.

How severe is CVE-2019-7192?

CVE-2019-7192 is a critical improper access control vulnerability with an EPSS score of 94.3% in the 99th percentile and confirmed ransomware exploitation. It enables unauthenticated remote access to QNAP NAS devices and serves as the entry point for a devastating four-vulnerability attack chain used by ransomware operators.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score88.21%
EPSS Percentile99.8%

Dates

PublishedDecember 5, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.