Q-Free MaxTime Hard-Coded Cryptographic Key Vulnerability Allowing Authentication Bypass

Vulnerability

A vulnerability exists in Q-Free MaxTime versions through 2.11.0, where a hard-coded cryptographic key is used in JSON Web Token (JWT) signing. This flaw allows an unauthenticated remote attacker to bypass authentication by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability allows for unauthorized access by bypassing authentication mechanisms.

Remediation

Until an official patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.