Q-Free MaxTime Path Traversal Vulnerability Allowing File Deletion

Vulnerability

A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0, specifically within the template deletion mechanism. This vulnerability allows authenticated remote attackers to delete sensitive files by sending crafted HTTP requests. The issue could lead to system instability or data loss.

Impact

Exploitation of this vulnerability could result in the unauthorized deletion of sensitive files, causing potential system instability or data loss.

Remediation

Until a patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.