CVE-2026-22900: QuNetSwitch
Published Mar 20, 2026
·Updated
A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access.
We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later
Affected Software
2 affected components
QuNetSwitch<2.0.5.0906
QNAP QuNetSwitch>=2.0.1.13077<2.0.5.0906
Remediation
Information
We have already fixed the vulnerability in the following version:
QuNetSwitch 2.0.5.0906 and later
Event History
Mar 20, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22900?
CVE-2026-22900 is considered a critical vulnerability due to the potential for remote unauthorized access.
2
How do I fix CVE-2026-22900?
To fix CVE-2026-22900, upgrade QuNetSwitch to version 2.0.5.0906 or later.
3
What type of vulnerability is CVE-2026-22900?
CVE-2026-22900 is a use of hard-coded credentials vulnerability.
4
Who is affected by CVE-2026-22900?
The vulnerability affects all users of QuNetSwitch versions prior to 2.0.5.0906.
5
What is the impact of exploiting CVE-2026-22900?
Exploitation of CVE-2026-22900 allows remote attackers to gain unauthorized access to the QuNetSwitch system.