Q-Free MaxTime Missing Authentication Vulnerability in Front Panel Authentication

Vulnerability

A vulnerability allowing unauthenticated remote attackers to disable front panel authentication has been identified in Q-Free MaxTime versions through 2.11.0. This issue arises from a missing authentication for critical functions, specifically in the maxprofile/setup/routes.lua file. Exploitation of this vulnerability could make physical access to the device easier by bypassing front panel security measures.

Impact

Disabling front panel authentication could facilitate unauthorized physical access to the device by removing a layer of security.

Remediation

While an official patch has not been released, it is recommended to restrict and monitor network access to the management web application on devices running Q-Free MaxTime versions through 2.11.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.