CVE-2025-26375
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Feb 12, 2025
Updated: Mar 3, 2025
CWE ID 862
Summary
CVE-2025-26375 is a vulnerability affecting Q-Free MaxTime version 2.11.0 and below. This issue, classified as CWE-862 "Missing Authorization," enables authenticated, low-privileged attackers to create new users with arbitrary privileges by exploiting a flaw in maxprofile/users/routes.lua. By manipulating crafted HTTP requests, the attacker can bypass the intended authorization checks and ultimately gain unauthorized access to higher-level functionalities within the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Q-Free Maxtime
Affected Vendors
- Nozomi Networks