Security ID : QSA-26-11
Multiple Vulnerabilities in QuNetSwitch (ADRA NDR)
Release date : March 21, 2026
CVE identifier : CVE-2026-22897 | CVE-2026-22900 | CVE-2026-22901 | CVE-2026-22902
Affected products: QuNetSwitch 2.0.x
Severity
Critical
Status
Resolved
Summary
Multiple vulnerabilities have been reported to affect QuNetSwitch.
- CVE-2026-22897: Remote attackers can exploit the command injection vulnerability to execute arbitrary commands.
- CVE-2026-22900: Remote attackers can exploit the use of hard-coded credentials vulnerability to gain unauthorized access.
- CVE-2026-22901: If a remote attacker gains a user account, they can then exploit the command injection vulnerability to execute arbitrary commands.
- CVE-2026-22902: If a local attacker gains an administrator account, they can then exploit the command injection vulnerability to execute arbitrary commands.
We have already fixed these vulnerabilities in the following versions:
| Affected Product | Fixed Version |
| QuNetSwitch 2.0.x | QuNetSwitch 2.0.4.0415 and later |
| QuNetSwitch 2.0.x | QuNetSwitch 2.0.5.0906 and later |
Recommendation
For optimal security and performance, we recommend regularly updating QuNetSwitch to the latest version, ensuring you receive all vulnerability fixes and new features. You can view the product support status to check for the latest updates available for your model.
Updating QuNetSwitch
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "QuNetSwitch" and then press ENTER.
QuNetSwitch appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your QuNetSwitch is already up to date. - Click OK.
The system updates the application.
Updating ADRA NDR
- Log in to ADRA NDR.
- Go to Firmware.
- Select Update now.
- Select Latest.
- Click Apply.
A confirmation message appears. - Click Apply.
ADRA NDR downloads and installs the latest firmware.
Tip: You can also download the latest firmware for your specific device from Download Center, and then perform a manual update in ADRA NDR by going to Firmware > Manual Update.
Attachment
Acknowledgements: YingMuo
Revision History:
V1.0 (March 21, 2026) - Published