Q-Free MaxTime Hard-Coded Password Vulnerability in Root Account Allowing Arbitrary Code Execution via SSH
Vulnerability
A vulnerability exists in Q-Free MaxTime versions through 2.11.0, where a hard-coded password for the root account enables unauthenticated remote attackers to execute arbitrary code with root privileges via SSH.
Impact
Exploitation of this vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges, potentially leading to a full system compromise.
Remediation
While an official patch has not been released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
6.6remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
