HIGH
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to disable front panel authentication via crafted HTTP requests
Published Feb 12, 2025
7.5
HIGHCVSS 3.1
EPSS 0.56%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.