CVE-2026-22902: QuNetSwitch
Published Mar 20, 2026
·Updated
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands.
We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later
Affected Software
2 affected components
QuNetSwitch<2.0.5.0906
QNAP QuNetSwitch<=2.0.5.0906
Remediation
Information
We have already fixed the vulnerability in the following version:
QuNetSwitch 2.0.5.0906 and later
Event History
Mar 20, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22902?
CVE-2026-22902 has been classified as a high severity command injection vulnerability.
2
How do I fix CVE-2026-22902?
To fix CVE-2026-22902, upgrade to QuNetSwitch version 2.0.5.0906 or later.
3
Who is affected by CVE-2026-22902?
CVE-2026-22902 affects users of QuNetSwitch versions prior to 2.0.5.0906.
4
What type of vulnerability is CVE-2026-22902?
CVE-2026-22902 is a command injection vulnerability that allows attackers to execute arbitrary commands.
5
Can CVE-2026-22902 be exploited remotely?
CVE-2026-22902 requires local access with an administrator account to exploit the vulnerability.