Q-Free MaxTime Unrestricted File Upload Vulnerability Allowing Arbitrary File Overwrite

Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in Q-Free MaxTime versions through 2.11.0. This issue allows authenticated remote attackers to upload malicious files via crafted HTTP requests. The vulnerability could be exploited to overwrite arbitrary files, potentially leading to system compromise or denial-of-service conditions.

Impact

Exploitation of this vulnerability could allow authenticated remote attackers to overwrite arbitrary files, with the potential for system compromise or causing a denial-of-service condition.

Remediation

An official solution has not been communicated by the vendor. However, it is recommended to restrict and monitor network access to the management web application exposed by devices running Q-Free MaxTime through 2.11.0, until a patch is released.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.