CVE-2025-26339

A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability in multiple unspecified ways via crafted HTTP requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:q-free:maxtime:*:*:*:*:*:*:*:*

History

24 Oct 2025, 14:58

Type Values Removed Values Added
CPE cpe:2.3:a:q-free:maxtime:*:*:*:*:*:*:*:*
References () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26339 - () https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26339 - Third Party Advisory
First Time Q-free
Q-free maxtime
Summary
  • (es) Un CWE-306 "Autenticación faltante para función crítica" en maxtime/handleRoute.lua en Q-Free MaxTime menor o igual a la versión 2.11.0 permite que un atacante remoto no autenticado afecte la confidencialidad, integridad o disponibilidad del dispositivo de múltiples formas no especificadas a través de solicitudes HTTP manipulado.

12 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 14:15

Updated : 2025-10-24 14:58


NVD link : CVE-2025-26339

Mitre link : CVE-2025-26339

CVE.ORG link : CVE-2025-26339


JSON object : View

Products Affected

q-free

  • maxtime
CWE
CWE-306

Missing Authentication for Critical Function