CVE-2019-7192 is a critical improper access control vulnerability affecting QNAP Photo Station and QTS, allowing remote attackers to gain unauthorized system access. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited, including in ransomware campaigns, and has publicly available exploit modules and significant community discussion, underscoring its immediate threat. QNAP recommends updating Photo Station to the latest versions to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.3CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 5.7.10CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 5.4.9CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | ||
< 5.2.11CPE matchmatch criteria | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.