CVE-2025-26351

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Feb 12, 2025
CWE ID 35

Summary

CVE-2025-26351 is a new vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue, classified as a CWE-35 "Path Traversal" flaw, enables authenticated remote attackers to read sensitive files through crafted HTTP requests. By exploiting the template download mechanism of the software, an attacker can traverse paths and access files that should normally be restricted. This vulnerability poses a significant risk to data confidentiality and could potentially lead to other security issues if left unpatched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks