HIGHCVE-2026-22897Published Modified CNA qnap
CVE-2026-22897: QuNetSwitch
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later
Metrics
- CVSS v4.0
- 8.1
- Severity
- HIGH
- Fixed in
- 2.0.4.0415
- Affected Products
- 1
Fix available
2.0.4.0415
Affected packages
- QNAP Systems Inc. / QuNetSwitch< 2.0.4.0415 (from 2.0.x)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:UReferences