June 8, 2022 · Applied Cybernetics Group
CVE-2019-7192 — QNAP Photo Station
known ransomware use
QNAP Photo Station Improper Access Control Vulnerability
- Added to KEV
2022-06-08- Federal due date
2022-06-22- Vendor
- QNAP
- Product
- Photo Station
- EPSS
- 100.0th percentile (score 0.943, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-7192
CISA short description
QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.
Required action
Apply updates per vendor instructions.