CVE-2026-22900

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qunetswitch:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) Se ha reportado una vulnerabilidad de uso de credenciales codificadas de forma rígida que afecta a QuNetSwitch. Los atacantes remotos pueden entonces explotar la vulnerabilidad para obtener acceso no autorizado. Ya hemos corregido la vulnerabilidad en la siguiente versión: QuNetSwitch 2.0.5.0906 y posteriores

25 Mar 2026, 21:07

Type Values Removed Values Added
First Time Qnap qunetswitch
Qnap
CPE cpe:2.3:a:qnap:qunetswitch:*:*:*:*:*:*:*:*
References () https://www.qnap.com/en/security-advisory/qsa-26-11 - () https://www.qnap.com/en/security-advisory/qsa-26-11 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

20 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 17:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22900

Mitre link : CVE-2026-22900

CVE.ORG link : CVE-2026-22900


JSON object : View

Products Affected

qnap

  • qunetswitch
CWE
CWE-798

Use of Hard-coded Credentials