### [CVE-2019-7192](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7192) ![](https://img.shields.io/static/v1?label=Product&message=QNAP%20NAS%20devices%20running%20Photo%20Station&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Access%20Control&color=brighgreen) ### Description This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. ### POC #### Reference - http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html - http://packetstormsecurity.com/files/157857/QNAP-QTS-And-Photo-Station-6.0.3-Remote-Command-Execution.html #### Github - https://github.com/0xT11/CVE-POC - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/HimmelAward/Goby_POC - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors - https://github.com/Z0fhack/Goby_POC - https://github.com/amcai/myscan - https://github.com/cycraft-corp/cve-2019-7192-check - https://github.com/d4n-sec/d4n-sec.github.io - https://github.com/developer3000S/PoC-in-GitHub - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/hwiwonl/dayone - https://github.com/lnick2023/nicenice - https://github.com/nomi-sec/PoC-in-GitHub - https://github.com/qazbnm456/awesome-cve-poc - https://github.com/th3gundy/CVE-2019-7192_QNAP_Exploit - https://github.com/xbl3/awesome-cve-poc_qazbnm456