Q-Free MaxTime Missing Authentication Vulnerability in Front Panel Authentication

Vulnerability

A vulnerability allowing unauthenticated remote attackers to enable front panel authentication has been identified in Q-Free MaxTime versions through 2.11.0. This issue, categorized as CWE-306 'Missing Authentication for Critical Function', resides in the file maxprofile/setup/routes.lua. Exploitation of this vulnerability could lock out legitimate users by manipulating HTTP requests to activate front panel authentication.

Impact

Enabling front panel authentication could disrupt access for legitimate users, potentially locking them out of the system.

Remediation

Until a patch is released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.