CVE-2025-26362
7.5HIGHA CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbit
Publicado: 2/12/2025Atualizado: 10/28/2025
Descrição
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to set an arbitrary authentication profile server via crafted HTTP requests.
Análise IADesenvolvido por IA
Produtos Afetados
q-freemaxtime
Referências
- https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26362Third Party Advisory