PT-2026-33926 · Quantum Networks · Quantum Networks Router
Arkino Robilin R
+5
·
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-41037
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Quantum Networks router (affected versions not specified)
Description
The web-based management interface lacks rate limiting and CAPTCHA protection for failed login attempts. This allows an attacker on the same network to perform brute force attacks against administrative credentials to gain unauthorized root access. Additionally, the management CLI is susceptible to command injection, which can lead to remote code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
OS Command Injection
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quantum Networks Router