CVE-2025-1100
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 12, 2025
CWE ID 259
Summary
CVE-2025-1100 is a critical vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue involves a hard-coded root password, a CWE-259 error, which can be exploited by unauthenticated attackers over SSH. Successful exploitation grants the attacker unrestricted root access and the ability to execute arbitrary code. This security flaw poses a significant risk and urges users to apply the necessary patches as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks