CVE-2025-26361
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-26361 is a vulnerability identified in Q-Free MaxTime's maxprofile/setup/routes.lua component, affecting versions 2.11.0 and below. This issue, classified as CWE-306 "Missing Authentication for Critical Function," allows unauthenticated remote attackers to perform a factory reset on the device by sending crafted HTTP requests. This vulnerability poses a significant risk as it does not require any form of authentication, enabling attackers to gain unrestricted access and alter critical configurations on the affected device. Successful exploitation could lead to data loss or unauthorized system modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks