Q-Free MaxTime Missing Authentication Vulnerability in Guest Mode
Vulnerability
A vulnerability allowing unauthenticated remote attackers to enable passwordless guest mode has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/guest-mode/routes.lua file. Exploitation involves sending crafted HTTP requests to the application.
Impact
Exploitation of this vulnerability allows unauthorized access by enabling passwordless guest mode, potentially leading to unauthorized actions or access within the application.
Remediation
Until a patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
