Q-Free MaxTime Missing Authorization Vulnerability Allowing User Deletion

Vulnerability

A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to delete users by sending crafted HTTP requests.

Impact

Exploitation of this vulnerability enables authenticated low-privileged remote attackers to delete users, potentially disrupting access to important accounts.

Remediation

Until an official patch is released, it is recommended to regularly review user and group configurations in the management web application of Q-Free MaxTime devices running versions through 2.11.0. Confirm that all settings are correct and remove any unnecessary accounts.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.