QNAP QuNetSwitch Hard-Coded Credentials Vulnerability Allowing Unauthorized Access

Vulnerability

A vulnerability in QuNetSwitch versions 2.0.x has been identified, involving hard-coded credentials that remote attackers can exploit to gain unauthorized access. This vulnerability has been resolved in QuNetSwitch version 2.0.5.0906 and later.

Impact

Exploitation of this vulnerability allows for unauthorized access to the affected system.

Remediation

Users can update QuNetSwitch through the QTS or QuTS hero App Center. For ADRA NDR users, the latest firmware can be downloaded from the QNAP Download Center or via the Firmware > Manual Update option in the ADRA NDR interface.

Added: Mar 20, 2026, 5:18 PM
Updated: Mar 20, 2026, 5:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.7
remediation
7.7
relevance
4.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.