Missing Authentication Vulnerability in Q-Free MaxTime Software
CVE-2025-26365
7.5HIGH
What is CVE-2025-26365?
A significant security weakness exists in Q-Free's MaxTime software prior to version 2.11.0, where a lack of authentication for pivotal functions could be exploited by an unauthenticated remote attacker. This vulnerability allows such attackers to send specially crafted HTTP requests, potentially enabling front panel authentication and compromising the security of the system.
Affected Version(s)
MaxTime 0 <= 2.11.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Giubertoni of Nozomi Networks found this bug during a security research activity.