CVE-2025-26375

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 12, 2025
Updated: Mar 3, 2025
CWE ID 862

Summary

CVE-2025-26375 is a vulnerability affecting Q-Free MaxTime version 2.11.0 and below. This issue, classified as CWE-862 "Missing Authorization," enables authenticated, low-privileged attackers to create new users with arbitrary privileges by exploiting a flaw in maxprofile/users/routes.lua. By manipulating crafted HTTP requests, the attacker can bypass the intended authorization checks and ultimately gain unauthorized access to higher-level functionalities within the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Q-Free Maxtime

Affected Vendors

  • Nozomi Networks