Q-Free MaxTime Missing Authentication Vulnerability in HTTP Request Handling

Vulnerability

A vulnerability allowing missing authentication for critical functions has been identified in Q-Free MaxTime versions through 2.11.0. This issue, located in the file maxtime/handleRoute.lua, enables an unauthenticated remote attacker to impact the device's confidentiality, integrity, or availability in various unspecified ways by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in device configuration or cause a denial-of-service condition.

Remediation

Until an official patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.