This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed login attempts in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing brute force attacks against administrative credentials, leading to unauthorized access with root privileges on the targeted device.
References
| Link | Resource |
|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0200 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
06 May 2026, 18:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:qntmnet:qn-i-470_firmware:6.1.1.b1:*:*:*:*:*:*:* cpe:2.3:h:qntmnet:qn-i-470:-:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
Qntmnet qn-i-470
Qntmnet Qntmnet qn-i-470 Firmware |
|
| References | () https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0200 - Patch, Vendor Advisory |
21 Apr 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-307 | |
| Summary | (en) This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed login attempts in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing brute force attacks against administrative credentials, leading to unauthorized access with root privileges on the targeted device. |
21 Apr 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 10:16
Updated : 2026-05-06 18:12
NVD link : CVE-2026-41037
Mitre link : CVE-2026-41037
CVE.ORG link : CVE-2026-41037
JSON object : View
Products Affected
qntmnet
- qn-i-470
- qn-i-470_firmware
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
