CVE-2026-22900

Severity CVSS v4.0:
MEDIUM
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
20/03/2026
Last modified:
25/03/2026

Description

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> QuNetSwitch 2.0.5.0906 and later

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnap:qunetswitch:*:*:*:*:*:*:*:* 2.0.1.13077 (including) 2.0.5.0906 (excluding)


References to Advisories, Solutions, and Tools