LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-7192: QNAP Photo Station Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-7192 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

CVE-2019-7192 is an improper access control vulnerability in QNAP Photo Station on QNAP NAS devices. It allows remote attackers to gain unauthorized access to the system. This matters because Photo Station is commonly exposed for media sharing, and the flaw has been used in ransomware campaigns. Teams should treat any internet-facing or poorly segmented instance as high priority until confirmed patched per the vendor advisory.

How it works

The weakness is CWE-863 (Incorrect Authorization). In products of this class, the application fails to properly enforce access-control decisions on certain requests or resources. An attacker who can reach the Photo Station service can abuse the flawed checks to obtain unauthorized access to the system without legitimate credentials or privileges. Public detail on exact request sequences or parameters is limited; defenders should treat any unauthenticated or weakly authenticated interaction with Photo Station as potentially abusive and confirm the precise attack surface against the vendor advisory. Successful exploitation can lead to broader system compromise on the NAS, which is why the issue has been leveraged by ransomware operators.

Am I affected? How to find it in your systems

QNAP Photo Station typically runs on QNAP NAS appliances used for file storage, media libraries, and remote access. Inventory every QNAP device on the network, including those in branch offices, labs, and cloud-adjacent environments. Check whether the Photo Station application is installed and enabled; review the device’s application list and service status through the QNAP management interface or supported inventory tools. Confirm the installed version and patch level directly against the vendor advisory, because specific affected ranges are not restated here. Look for devices with Photo Station reachable from untrusted networks, especially if port forwarding, UPnP, or reverse-proxy rules expose it.

For signs of exploitation, review NAS logs, web-server access logs associated with Photo Station, and authentication or authorization failure events for anomalous remote requests that succeed or that target media-related endpoints. Correlate with unexpected account creation, privilege changes, file encryption activity, or outbound connections typical of ransomware. Endpoint detection and network telemetry that flag unusual access to NAS shares can also surface post-exploitation behavior. If logs are sparse, assume exposure until proven otherwise and prioritize scanning and isolation.

How to remediate

Patch first. Apply the updates published by QNAP for Photo Station exactly as described in the vendor advisory and follow CISA’s required action to apply updates per vendor instructions. After updating, verify the new version is running and that Photo Station services restarted cleanly. Remove or disable Photo Station entirely if the business no longer requires it. Harden remaining instances by restricting access to trusted networks only, enforcing strong authentication, and disabling unnecessary sharing or guest features. Review and tighten NAS firewall rules, disable unused applications, and ensure the device itself is on a supported firmware baseline. Document the change and re-scan to confirm the vulnerability is no longer present.

If you can't patch immediately

Reduce exposure immediately. Segment the NAS so Photo Station is unreachable from the internet and from untrusted internal segments; place it behind a firewall or VPN that permits only authorized administrative and user traffic. If a web application firewall or reverse proxy sits in front of the service, apply virtual-patching rules that block anomalous or unauthorized access patterns characteristic of improper-authorization abuses—tune these against the vendor’s description rather than generic signatures. Disable Photo Station or its remote-access features until the patch can be installed. Increase monitoring: alert on any access to Photo Station endpoints, failed or unexpected authorization events, large-scale file reads or encrypts, and new process execution on the NAS. Maintain offline or immutable backups of critical data so ransomware impact can be contained. These steps buy time but do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities of this type frequently lead to ransomware and data theft. If your QNAP Photo Station instance was reachable and unpatched, assume possible unauthorized access and investigate for encryption, data exfiltration, or persistence. Rotate credentials, review share permissions, and restore from known-good backups if needed. You can run a free exposure scan of your email addresses to check whether associated accounts appear in known breach data sets and take further account-hardening steps accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQNAP · Photo Station
WeaknessCWE-863
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities