Known vulnerabilities in QuNetSwitch
Vendor:
QNAP Systems, Inc.
Software:
QuNetSwitch
Software CPE:
cpe:2.3:h:qnap_systems:qunetswitch:*:*:*:*:*:*:*:*
Website:
https://www.qnap.com
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124225 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-22902 |
CWE-78 | Low | 2.0.4.0415, 2.0.5.0906 | 23.03.2026 |
SB2026032345 |
||
| #VU124224 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-22901 |
CWE-78 | Medium | 2.0.4.0415, 2.0.5.0906 | 23.03.2026 |
SB2026032345 |
||
| #VU124223 - Use of Hard-coded Credentials CVE-2026-22900 |
CWE-798 | High | 2.0.4.0415, 2.0.5.0906 | 23.03.2026 |
SB2026032345 |
||
| #VU124220 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-22897 |
CWE-78 | High | 2.0.4.0415, 2.0.5.0906 | 23.03.2026 |
SB2026032345 |
||
| #VU56446 - Insufficiently Protected Credentials CVE-2021-28813 |
CWE-522 | Medium | 1.0.6.1509, 1.0.6.1519 | 10.09.2021 |
SB2021091006 |