Q-Free MaxTime Path Traversal Vulnerability Allowing File Deletion

Vulnerability

A path traversal vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated remote attackers to delete sensitive files by sending crafted HTTP requests. The issue is located in the 'maxtime/api/database/database.lua' file.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of sensitive files, causing potential system instability or data loss.

Remediation

No official solution has been communicated by the vendor. However, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0, until a patch is released.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.