S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 28, 2025

CVE-2019-7194 Scanner

CVE-2019-7194 Scanner - Remote Code Execution vulnerability in QNAP Photo Station

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-7194
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
QNAP NAS devices running Photo Stationby n/a
QTS 4.4.1: Photo Station before version 6.0.3, QTS 4.3.4 - QTS 4.4.0: Photo Station before version 5.7.10, QTS 4.3.0 - QTS 4.3.3: Photo Station before version 5.4.9, QTS 4.2.6: Photo Station before version 5.2.11
Updated Aug 21, 2026View on NVD →
Detail

QNAP Photo Station is widely used by individuals and businesses to manage and organize photo collections on their QNAP network-attached storage devices. It allows users to upload, view, and share photos through an organized interface, facilitating media management tasks. Users benefit from features like thumbnail generation, slideshow, and web access to their photo libraries. Primarily targeted at photographers, enterprises dealing with media, and personal users, it integrates seamlessly with QNAP NAS systems. This application supports various formats and allows for easy search and categorization of media files. Employing a straightforward user interface, QNAP Photo Station is a valuable tool for digital photo handling.

The Remote Code Execution (RCE) vulnerability allows attackers to execute arbitrary code on the host machine running QNAP Photo Station. Attackers can potentially gain control over affected devices by exploiting such vulnerabilities, usually targeting network-connected devices. It occurs when an application, such as QNAP Photo Station, fails to sufficiently validate or sanitize user inputs before incorporation into web requests or commands. This could allow attackers to run malicious scripts on the server. RCE vulnerabilities are critical as they could compromise system integrity and confidentiality completely. Often, these vulnerabilities require chaining multiple exploits to bypass security features and obtain execution capabilities.

Technical details of this vulnerability involve multiple stages where attackers exploit the software's directory traversal and authentication mechanisms to leverage access for code execution. Initial steps include obtaining a valid album ID and necessary tokens like PHPSESSID and app_token, which are key to manipulating server operations. The endpoint becomes vulnerable during the flawed authorization process, allowing traversal of server directories. The attack detailed involves writing a PHP payload into specific file paths by manipulating SMTP settings misconfigurations. Finally, this payload can be triggered to execute commands via manipulated slideshow paths, providing attackers with unauthorized system access.

Once exploited, this vulnerability could allow hijackers to install backdoors, control the server remotely, or access sensitive information stored on the NAS. Such actions could lead to unauthorized data manipulation or exposure, disruption of service, and potential installation of malicious software. Servers could be added to botnets, potentially launching attacks on other systems or devices. Additionally, the breach of confidentiality and integrity of user data stored on the NAS is significant. Malicious actors might use this access to compromise connected networks or exfiltrate sensitive personal or organizational data.

REFERENCES

Solution Advice
  • Update QNAP Photo Station to version 6.0.3 or later to patch the RCE vulnerability.
  • Configure strong access controls and authentication mechanisms on NAS devices.
  • Regularly review and apply security updates released by QNAP for their products.
  • Conduct routine security audits and penetration testing to identify vulnerabilities early.
  • Ensure proper network segmentation to limit the impact of potential breaches.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-7194 Scanner - Remote Code Execution vulnerability in QNAP Photo Station | S4E