CVE-2019-7192: QNAP Photo Station Improper Access Control Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 88.1% chance of exploitation in the next 30 days.

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Affected products

  • QNAP Photo Station: before 6.0.3 (fixed in 6.0.3); before 5.7.10 (fixed in 5.7.10); before 5.4.9 (fixed in 5.4.9); before 5.2.11 (fixed in 5.2.11)

Published 2019-12-05. Last modified 2026-06-17.