Missing Authentication Vulnerability in Q-Free MaxTime Product
CVE-2025-26361

9.1CRITICAL

Key Information:

Vendor

Q-free

Status
Vendor
CVE Published:
12 February 2025

What is CVE-2025-26361?

A significant security flaw in Q-Free MaxTime, present in versions up to 2.11.0, can be exploited by unauthenticated remote attackers. This vulnerability allows the attackers to execute crafted HTTP requests that can trigger a factory reset of the device, leading to potential unauthorized access and disruption of service. It highlights the need for robust authentication measures in critical functionalities to prevent unauthorized operations.

Affected Version(s)

MaxTime 0 <= 2.11.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Giubertoni of Nozomi Networks found this bug during a security research activity.
.