CVE-2026-41036 is a command injection vulnerability in Quantum Networks routers stemming from insufficient input validation in the management CLI interface. An authenticated remote attacker can inject arbitrary operating system commands to achieve remote code execution with root-level privileges on affected devices. The vulnerability requires valid authentication credentials for exploitation, making it a network-adjacent attack vector with moderate complexity. Successful compromise would grant an attacker complete control over the router with the highest privilege level, potentially enabling further network infiltration, data interception, or service disruption. Current exploitation activity is minimal, with the vulnerability classified as inactive on public exploit lists and not included in the Known Exploited Vulnerabilities catalog. The EPSS score of 0.004 indicates low real-world exploitation probability, and the FAUCET risk score of 51.0/100 suggests moderate organizational concern. No publicly available exploit code has been documented at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1.1.b1CPE matchmatch criteria | cpe:2.3:o:qntmnet:qn-i-470_firmware:6.1.1.b1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.