CVE-2025-26362
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 12, 2025
CWE ID 306
Summary
CVE-2025-26362 is a critical vulnerability affecting Q-Free MaxTime versions 2.11.0 and below. This issue, classified as CWE-306 "Missing Authentication for Critical Function," enables unauthenticated attackers to manipulate authentication profiles through crafted HTTP requests. By exploiting this missing authentication in the maxprofile/setup/routes.lua file, adversaries can set arbitrary authentication profiles, posing a significant security risk. Successful exploitation may lead to unauthorized access, data breaches, or other malicious activities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks