CVE-2025-26363
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 12, 2025
CWE ID 306
Summary
CVE-2025-26363 is a vulnerability with a "Missing Authentication for Critical Function" classification, affecting Q-Free MaxTime versions 2.11.0 and below. This issue resides in maxprofile/setup/routes.lua and enables an unauthenticated remote attacker to manipulate authentication profile servers through crafted HTTP requests, posing a risk to system security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks