CVE-2026-41037 is a brute force vulnerability affecting Quantum Networks routers, specifically targeting the web-based management interface due to the absence of rate limiting and CAPTCHA protections on failed login attempts. This flaw enables attackers positioned on the same network to conduct credential attacks against administrative accounts, potentially resulting in complete system compromise with root-level access. The vulnerability presents a network-based attack vector with low complexity, though the EPSS score of 0.00022 indicates relatively low exploitation probability in the wild. Currently, there is no evidence of active exploitation, the vulnerability is not listed on known exploit databases, and community attention appears minimal as indicated by its inactive status on vulnerability tracking lists. The FAUCET Risk Score of 42.0 out of 100 suggests moderate concern for organizations operating Quantum Networks equipment, particularly those with multiple devices on shared network segments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1.1.b1CPE matchmatch criteria | cpe:2.3:o:qntmnet:qn-i-470_firmware:6.1.1.b1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.