CVE-2025-26360
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 12, 2025
CWE ID 306
Summary
CVE-2025-26360 is a vulnerability classified as CWE-306 "Missing Authentication for Critical Function." In Q-Free MaxTime versions 2.11.0 and below, the maxprofile/persistance/routes.lua file contains a critical function lacking authentication. An unauthenticated attacker can exploit this vulnerability by crafting malicious HTTP requests, resulting in the deletion of dashboard configurations. This issue poses a significant risk, as unauthorized deletion of critical configurations can disrupt operations and compromise data integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks