CVE-2025-26349

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 23

Summary

CVE-2025-23649 is a vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. An authenticated attacker can exploit this CWE-23 "Relative Path Traversal" flaw in the file upload mechanism to overwrite arbitrary files through crafted HTTP requests. This issue poses a significant risk, especially in environments where untrusted users are granted access to the affected system. Successful exploitation could lead to data corruption or unauthorized access to sensitive files. It's recommended to update to the latest version of Q-Free MaxTime to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks