Q-Free MaxTime Missing Authentication Vulnerability Allowing Dashboard Deletion

Vulnerability

A vulnerability exists in Q-Free MaxTime versions through 2.11.0, specifically within the maxprofile/persistance/routes.lua file. This vulnerability, categorized as CWE-306 'Missing Authentication for Critical Function', enables an unauthenticated remote attacker to delete dashboards by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability allows for the unauthorized deletion of dashboards, potentially disrupting operations or causing the loss of important data.

Remediation

While an official patch has not been announced, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.