CVE-2026-41039
Improper Access Control in Quantum Networks Router Exposes Sensitive Data
Publication date: 2026-04-21
Last updated on: 2026-05-06
Assigner: Indian Computer Emergency Response Team (CERT-In)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qntmnet | qn-i-470_firmware | 6.1.1.b1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows an unauthenticated attacker to access sensitive information on the targeted device due to improper access control and insecure default configuration.
Such unauthorized access to sensitive information could potentially lead to non-compliance with common standards and regulations like GDPR and HIPAA, which require protection of sensitive data and strict access controls.
Can you explain this vulnerability to me?
This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management interface.
An unauthenticated attacker could exploit this vulnerability by accessing exposed API endpoints on the targeted device.
Successful exploitation could allow the attacker to access sensitive information, including internal endpoints, scripts, and directories on the targeted device.
How can this vulnerability impact me? :
Exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information stored on the Quantum Networks router.
- Access to internal endpoints
- Access to scripts
- Access to directories on the targeted device
This could lead to further attacks or compromise of the network managed by the device.