PT-2025-7128 · Q Free · Q-Free Maxtime

Andrea Palanca

+1

·

Published

2025-02-12

·

Updated

2025-10-24

·

CVE-2025-26339

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Q-Free MaxTime versions prior to 2.11.0
Description: A missing authentication issue for a critical function in maxtime/handleRoute.lua allows an unauthenticated remote attacker to affect device confidentiality, integrity, or availability via crafted HTTP requests.
Recommendations: For versions prior to 2.11.0, update to version 2.11.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the handleRoute.lua function until a patch is available. Avoid using the vulnerable function to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-26339

Affected Products

Q-Free Maxtime