S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-7192 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in QNAP NAS devices running Photo Station affects v. QTS 4.4.1: Photo Station before version 6.0.3, QTS 4.3.4 - QTS 4.4.0: Photo Station before version 5.7.10, QTS 4.3.0 - QTS 4.3.3: Photo Station before version 5.4.9, QTS 4.2.6: Photo Station before version 5.2.11.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-7192
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
QNAP NAS devices running Photo Stationby n/a
QTS 4.4.1: Photo Station before version 6.0.3, QTS 4.3.4 - QTS 4.4.0: Photo Station before version 5.7.10, QTS 4.3.0 - QTS 4.3.3: Photo Station before version 5.4.9, QTS 4.2.6: Photo Station before version 5.2.11
Updated Aug 21, 2026View on NVD →
Detail

QNAP is a provider of Network Attached Storage (NAS) devices that are designed to meet the data storage needs of businesses. One of the most popular QNAP NAS features is Photo Station, an application that allows users to easily organize and share photos from their devices. With Photo Station, photos can be accessed from anywhere and shared with friends, family, or collaborators. 

However, QNAP recently announced that Photo Station had a serious security vulnerability, known as CVE-2019-7192. This vulnerability allowed attackers to gain unauthorized access to sensitive information stored on the device, including private photos, user data, and passwords. The vulnerability affected all versions of Photo Station prior to the latest version, making it a critical issue that required immediate attention.

If this vulnerability is exploited, the consequences can be dire. Attackers can gain access to user data and photos, which can be used for identity theft or other malicious purposes. Private information, such as passwords or personal correspondence, could also be revealed and result in significant harm. This vulnerability could lead to a major setback for businesses that rely on Photo Station to store and share important data.

In conclusion, if you are a QNAP NAS user who relies on Photo Station, it is essential to take these precautions to protect your data. Fortunately, by using a reputable security platform such as s4e.io, you can stay informed of any vulnerabilities or issues with your digital assets and take action before it’s too late. Don't leave your data exposed, take action today.

 

REFERENCES

Solution Advice

Fortunately, there are precautions that users can take to protect against this vulnerability. Here are some steps that should be taken:

  • Ensure that the latest version of Photo Station is installed.
  • Disable Guest user accounts if they are not needed.
  • Limit access to the device to trusted individuals only.
  • Use strong passwords and enable two-factor authentication.
  • Regularly monitor the device for any signs of suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.