CVE-2025-26349
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2025-23649 is a vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. An authenticated attacker can exploit this CWE-23 "Relative Path Traversal" flaw in the file upload mechanism to overwrite arbitrary files through crafted HTTP requests. This issue poses a significant risk, especially in environments where untrusted users are granted access to the affected system. Successful exploitation could lead to data corruption or unauthorized access to sensitive files. It's recommended to update to the latest version of Q-Free MaxTime to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks