CVE-2025-1101

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 12, 2025
CWE ID 204

Summary

CVE-2025-1101 is a newly discovered vulnerability in Q-Free MaxTime's login page, affecting versions 2.11.0 and below. This issue is classified as a CWE-204 "Observable Response Discrepancy," enabling an unauthenticated attacker to enumerate valid usernames through carefully crafted HTTP requests. This vulnerability could potentially be exploited to launch targeted attacks on specific users or gain unauthorized access to protected systems. It is recommended that affected organizations upgrade to the latest version of Q-Free MaxTime to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks