CVE-2025-26361

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 306

Summary

CVE-2025-26361 is a vulnerability identified in Q-Free MaxTime's maxprofile/setup/routes.lua component, affecting versions 2.11.0 and below. This issue, classified as CWE-306 "Missing Authentication for Critical Function," allows unauthenticated remote attackers to perform a factory reset on the device by sending crafted HTTP requests. This vulnerability poses a significant risk as it does not require any form of authentication, enabling attackers to gain unrestricted access and alter critical configurations on the affected device. Successful exploitation could lead to data loss or unauthorized system modifications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks