CVE-2026-41039
Received
Received - Intake
Improper Access Control in Quantum Networks Router Exposes Sensitive Data
Publication date: 2026-04-21
Last updated on: 2026-05-06
Assigner: Indian Computer Emergency Response Team (CERT-In)
Description
Description
This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management interface. An unauthenticated attacker could exploit this vulnerability by accessing exposed API endpoints on the targeted device.
Successful exploitation of this vulnerability could allow the attacker to access sensitive information, including internal endpoints, scripts and directories on the targeted device.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qntmnet | qn-i-470_firmware | 6.1.1.b1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |