CVE-2025-26362

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 306

Summary

CVE-2025-26362 is a critical vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue, classified as CWE-306 "Missing Authentication for Critical Function," enables unauthenticated attackers to manipulate authentication profiles through crafted HTTP requests. By exploiting this missing authentication in the maxprofile/setup/routes.lua file, adversaries can set arbitrary authentication profiles, posing a significant security risk. Successful exploitation may lead to unauthorized access, data breaches, or other malicious activities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks