CVE-2025-26345

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 12, 2025
Updated: Feb 18, 2025
CWE ID 306

Summary

CVE-2025-26345 is a vulnerability identified in Q-Free MaxTime's maxprofile/menu/routes.lua component, affecting versions 2.11.0 and below. This issue, classified as CWE-306 "Missing Authentication for Critical Function," enables an unauthenticated attacker to manipulate user group permissions through carefully crafted HTTP requests, thereby posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks