CVE-2025-26351
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Feb 12, 2025
CWE ID 35
Summary
CVE-2025-26351 is a new vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue, classified as a CWE-35 "Path Traversal" flaw, enables authenticated remote attackers to read sensitive files through crafted HTTP requests. By exploiting the template download mechanism of the software, an attacker can traverse paths and access files that should normally be restricted. This vulnerability poses a significant risk to data confidentiality and could potentially lead to other security issues if left unpatched.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks