Q-Free MaxTime Path Traversal Vulnerability Allowing Sensitive File Read

Vulnerability

A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to read sensitive files by sending crafted HTTP requests. The issue is located in the maxtime/api/sql/sql.lua file.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files, potentially exposing confidential information.

Remediation

No official patch has been communicated by the vendor. However, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0, until a patch is available.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.