CVE-2026-22897: QuNetSwitch
Published Mar 20, 2026
·Updated
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later
Affected Software
2 affected components
QuNetSwitch QuNetSwitch<2.0.4.0415
QNAP QuNetSwitch>=2.0.1.13077<2.0.4.0415
Remediation
Information
We have already fixed the vulnerability in the following version:
QuNetSwitch 2.0.4.0415 and later
Event History
Mar 20, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22897?
CVE-2026-22897 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2026-22897?
To fix CVE-2026-22897, upgrade to QuNetSwitch version 2.0.4.0415 or later.
3
Which versions of QuNetSwitch are affected by CVE-2026-22897?
CVE-2026-22897 affects QuNetSwitch versions prior to 2.0.4.0415.
4
What type of vulnerability is CVE-2026-22897?
CVE-2026-22897 is a command injection vulnerability that allows attackers to execute arbitrary commands remotely.
5
Can CVE-2026-22897 be exploited remotely?
Yes, CVE-2026-22897 can be exploited remotely by attackers to compromise the system.