Command Injection Vulnerability in QuNetSwitch by QNAP
CVE-2026-22902
5.7MEDIUM
What is CVE-2026-22902?
A command injection vulnerability exists in QuNetSwitch, enabling local attackers with administrator access to execute arbitrary commands on the system. This flaw poses a significant security risk, allowing unauthorized actions that could compromise the integrity and confidentiality of the system. Users are advised to upgrade to QuNetSwitch version 2.0.5.0906 or later to mitigate this issue.
Affected Version(s)
QuNetSwitch 2.0.x < 2.0.5.0906