Q-Free MaxTime Missing Authentication Vulnerability in User Group Permissions Management

Vulnerability

A vulnerability allowing unauthenticated remote attackers to edit user group permissions has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the file maxprofile/menu/routes.lua. Exploitation of this vulnerability could lead to unauthorized changes in user access rights, potentially escalating privileges or restricting access for legitimate users.

Impact

Exploitation of this vulnerability allows for unauthorized editing of user group permissions, which could escalate privileges or restrict access for legitimate users.

Remediation

Until a patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.