CVE-2019-7192
QNAP Photo Station Improper Access Control Vulnerability
Description
CVE-2019-7192 is an improper access control vulnerability in QNAP Photo Station that allows remote attackers to gain unauthorized access to QNAP NAS devices. The flaw enables attackers to bypass authentication and access control mechanisms, reaching system resources without valid credentials. Successful exploitation of this QNAP vulnerability can lead to unauthorized data access, configuration changes, and serve as an entry point for further attacks. CISA has added CVE-2019-7192 to its Known Exploited Vulnerabilities catalog with confirmed ransomware usage, and with an EPSS score of 94.3% (99th percentile), this represents one of the most actively exploited QNAP vulnerabilities.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| qnap | photo station | < 6.0.3; < 5.7.10; < 5.4.9; < 5.2.11 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- https://www.qnap.com/zh-tw/security-advisory/nas-201911-25(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7192(US Government Resource)
Weakness Type
CWE-284: Improper Access Control
CVE-2019-7192 exploits an improper access control weakness in QNAP Photo Station, where the application fails to properly restrict access to resources from unauthorized actors. This allows remote attackers to bypass authentication requirements and access system-level functionality on the QNAP NAS device without providing valid credentials, undermining the fundamental security boundary of the device.
Learn more: CWE-284 — Improper Access Control
Impact Analysis
CVE-2019-7192 is a critical vulnerability in QNAP Photo Station that allows remote attackers to bypass access controls and gain unauthorized access to the NAS device. The vulnerability requires no authentication and has low attack complexity, making it trivially exploitable by any attacker with network access. Confidentiality is critically impacted as unauthorized access enables reading sensitive files, credentials, and all data stored on the NAS. Integrity is compromised through the ability to modify system settings and stored data. Availability is directly threatened as CISA has confirmed ransomware usage associated with this vulnerability. The EPSS score of 94.3% (99th percentile) indicates near-certain exploitation activity. CVE-2019-7192 is the foundational vulnerability in the QNAP Photo Station attack chain (CVE-2019-7192 through CVE-2019-7195), providing the initial access that enables exploitation of the companion path traversal and input validation vulnerabilities.
Exploit Maturity
CVE-2019-7192 has reached maximum exploit maturity with CISA confirming active exploitation and known ransomware usage. The EPSS score of 94.3% (99th percentile) — the highest in the QNAP vulnerability cluster — reflects near-certain exploitation probability. This vulnerability serves as the initial access vector in the chain of four QNAP Photo Station vulnerabilities (CVE-2019-7192 through CVE-2019-7195) that ransomware operators have systematically exploited. Multiple ransomware families have been observed targeting internet-exposed QNAP NAS devices, using this improper access control vulnerability to establish an initial foothold before leveraging the path traversal and code injection vulnerabilities for full device compromise and data encryption.
Remediation
- Update QNAP Photo Station immediately to the latest patched version as required by the CISA KEV catalog. Consult the QNAP Security Advisory for specific version details.
- Remove QNAP NAS from direct internet exposure immediately — this is the most critical mitigation. Disable UPnP, remove port forwarding rules, and disable myQNAPcloud if not strictly required.
- Implement VPN-only remote access to the QNAP NAS, ensuring that no QNAP web interfaces are directly reachable from the public internet.
- Review and strengthen access controls on the NAS, including disabling unnecessary Photo Station accounts, enforcing strong passwords, and enabling two-factor authentication where available.
- Implement and verify a 3-2-1 backup strategy with at least one completely offline backup copy, given the confirmed ransomware threat associated with this vulnerability cluster.
Technical Details
CVE-2019-7192 is an improper access control vulnerability in QNAP Photo Station that allows remote attackers to bypass the application's authentication and authorization mechanisms. The Photo Station application fails to properly verify that incoming requests originate from authenticated and authorized users, allowing unauthenticated attackers to access protected resources and functionality. The access control bypass provides an initial foothold that attackers use in combination with the path traversal vulnerabilities (CVE-2019-7194, CVE-2019-7195) and input validation flaw (CVE-2019-7193) to achieve comprehensive NAS compromise. The vulnerability is exploitable through standard HTTP requests to the Photo Station web interface, requiring no special tools or sophisticated exploitation techniques. Given that QNAP NAS devices often store critical business data and personal files, and are frequently exposed to the internet through automatic port forwarding features, the impact of this access control bypass extends to the security of all data on the device.
Frequently Asked Questions
Is CVE-2019-7192 being actively exploited?
Yes. CISA has confirmed active exploitation with documented ransomware usage. The EPSS score of 94.3% (99th percentile) indicates near-certain exploitation. This is the primary access control bypass in the QNAP vulnerability cluster actively targeted by ransomware operators.
What products are affected by CVE-2019-7192?
CVE-2019-7192 affects QNAP NAS devices running Photo Station. All versions prior to the security fix are vulnerable. The full range of QNAP NAS models is affected regardless of hardware specifications.
How do I fix CVE-2019-7192?
Update QNAP Photo Station to the latest patched version immediately. As a critical first step, remove the NAS from direct internet exposure and implement VPN-only remote access. Maintain verified offline backups to protect against ransomware.
How severe is CVE-2019-7192?
CVE-2019-7192 is a critical improper access control vulnerability with an EPSS score of 94.3% in the 99th percentile and confirmed ransomware exploitation. It enables unauthenticated remote access to QNAP NAS devices and serves as the entry point for a devastating four-vulnerability attack chain used by ransomware operators.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.