CVE-2025-26360

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 12, 2025
CWE ID 306

Summary

CVE-2025-26360 is a vulnerability classified as CWE-306 "Missing Authentication for Critical Function." In Q-Free MaxTime versions 2.11.0 and below, the maxprofile/persistance/routes.lua file contains a critical function lacking authentication. An unauthenticated attacker can exploit this vulnerability by crafting malicious HTTP requests, resulting in the deletion of dashboard configurations. This issue poses a significant risk, as unauthorized deletion of critical configurations can disrupt operations and compromise data integrity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks