Q-Free MaxTime Weak Authentication Vulnerability in PIN Mechanism Allowing Brute-Force Attacks

Vulnerability

A weak authentication vulnerability has been identified in the PIN authentication system of Q-Free MaxTime versions through 2.11.0. This vulnerability allows unauthenticated remote attackers to brute-force user PINs by sending multiple crafted HTTP requests. Exploitation of this vulnerability could lead to unauthorized access to user accounts.

Impact

Exploitation of this vulnerability could allow an unauthenticated remote attacker to brute-force user PINs, potentially gaining unauthorized access to user accounts.

Remediation

Until an official patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.