Q-Free MaxTime Missing Authentication Vulnerability in Authentication Profile Server
Vulnerability
A vulnerability allowing unauthenticated remote attackers to disable an authentication profile server has been identified in Q-Free MaxTime versions through 2.11.0. This issue, categorized as CWE-306 'Missing Authentication for Critical Function', arises in the maxprofile/setup/routes.lua file, where the lack of proper authentication allows for exploitation via crafted HTTP requests.
Impact
Exploitation of this vulnerability disrupts authentication and access control by allowing unauthorized users to disable the authentication profile server.
Remediation
While an official patch has not been released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
