📦 Maxtime

by Q Free

🔍 What is Maxtime?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-26359

CRITICAL CVSS 9.8 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to reset user PINs in Q-Free MaxTime systems via crafted HTTP requests. It affects all Q-Free MaxTime installations running version 2.11.0 or...

CVE-2025-26361

CRITICAL CVSS 9.1 Feb 12, 2025

CVE-2025-26361 allows unauthenticated remote attackers to factory reset Q-Free MaxTime devices via crafted HTTP requests due to missing authentication on critical functions. This affects all Q-Free Ma...

CVE-2025-26344

CRITICAL CVSS 9.8 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to enable passwordless guest mode in Q-Free MaxTime systems via crafted HTTP requests. It affects all Q-Free MaxTime installations running ve...

CVE-2025-26347

CRITICAL CVSS 9.8 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to edit user permissions in Q-Free MaxTime traffic management systems via crafted HTTP requests. It affects all Q-Free MaxTime installations ...

CVE-2025-26339

CRITICAL CVSS 9.8 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to send crafted HTTP requests to Q-Free MaxTime traffic management systems, potentially compromising device confidentiality, integrity, and a...

CVE-2025-26341

CRITICAL CVSS 9.8 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to reset arbitrary user passwords in Q-Free MaxTime systems via crafted HTTP requests. It affects all installations running version 2.11.0 or...

CVE-2025-1100

CRITICAL CVSS 9.8 Feb 12, 2025

CVE-2025-1100 is a critical vulnerability in Q-Free MaxTime traffic management software where a hard-coded root password allows unauthenticated remote attackers to gain complete system control via SSH...

CVE-2025-26378

HIGH CVSS 8.8 Feb 12, 2025

A missing authorization vulnerability in Q-Free MaxTime allows authenticated low-privileged users to reset passwords, including administrator accounts, via crafted HTTP requests. This affects all inst...

CVE-2025-26371

HIGH CVSS 8.8 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to add users to groups in Q-Free MaxTime systems via crafted HTTP requests. It affects Q-Free MaxTime versions up to and including 2.11...

CVE-2025-26372

HIGH CVSS 7.1 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to remove users from groups in Q-Free MaxTime systems via crafted HTTP requests. It affects Q-Free MaxTime versions up to and including...

CVE-2025-26375

HIGH CVSS 8.8 Feb 12, 2025

This vulnerability allows authenticated low-privileged users in Q-Free MaxTime systems to create new user accounts with arbitrary administrative privileges through crafted HTTP requests. It affects al...

CVE-2025-26377

HIGH CVSS 8.1 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to delete user accounts in Q-Free MaxTime systems via crafted HTTP requests. It affects all installations running version 2.11.0 or ear...

CVE-2025-26364

HIGH CVSS 7.5 Feb 12, 2025

An unauthenticated remote attacker can disable authentication profile servers in Q-Free MaxTime traffic management systems by sending crafted HTTP requests. This affects all Q-Free MaxTime installatio...

CVE-2025-26365

HIGH CVSS 7.5 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to enable front panel authentication on Q-Free MaxTime systems via crafted HTTP requests. It affects Q-Free MaxTime versions up to and includ...

CVE-2025-26366

HIGH CVSS 7.5 Feb 12, 2025

An unauthenticated remote attacker can disable front panel authentication in Q-Free MaxTime systems via crafted HTTP requests. This affects all Q-Free MaxTime installations running version 2.11.0 or e...

CVE-2025-26368

HIGH CVSS 8.1 Feb 12, 2025

A missing authorization vulnerability in Q-Free MaxTime allows authenticated low-privileged users to delete user groups via crafted HTTP requests. This affects all installations running version 2.11.0...

CVE-2025-26369

HIGH CVSS 8.8 Feb 12, 2025

A missing authorization vulnerability in Q-Free MaxTime allows authenticated low-privileged users to escalate privileges by adding permissions to user groups via crafted HTTP requests. This affects al...

CVE-2025-26370

HIGH CVSS 7.1 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to remove privileges from user groups in Q-Free MaxTime traffic management systems. Attackers can escalate privileges or disrupt operat...

CVE-2025-26356

HIGH CVSS 7.2 Feb 12, 2025

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to overwrite sensitive files by manipulating file paths in HTTP requests. It affects Q-Free MaxTime versions u...

CVE-2025-26363

HIGH CVSS 7.5 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to enable authentication profile servers in Q-Free MaxTime traffic management systems via crafted HTTP requests. It affects all Q-Free MaxTim...

CVE-2025-26354

HIGH CVSS 7.2 Feb 12, 2025

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to overwrite sensitive files by manipulating file paths in HTTP requests to the copy endpoint. It affects all ...

CVE-2025-26343

HIGH CVSS 8.1 Feb 12, 2025

This vulnerability allows unauthenticated remote attackers to brute-force user PINs in Q-Free MaxTime parking management systems via crafted HTTP requests. Attackers can gain unauthorized access to sy...

CVE-2025-26349

HIGH CVSS 7.2 Feb 12, 2025

This vulnerability allows authenticated remote attackers to overwrite arbitrary files on Q-Free MaxTime systems by exploiting a relative path traversal flaw in the file upload mechanism. Attackers can...

CVE-2025-26373

MEDIUM CVSS 6.5 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to enumerate user accounts in Q-Free MaxTime systems via crafted HTTP requests to the user endpoint. It affects organizations using Q-F...

CVE-2025-26376

MEDIUM CVSS 6.5 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to modify user data in Q-Free MaxTime systems via crafted HTTP requests. It affects all installations running version 2.11.0 or earlier...

CVE-2025-26367

MEDIUM CVSS 4.3 Feb 12, 2025

This vulnerability allows authenticated low-privileged attackers to create arbitrary user groups in Q-Free MaxTime traffic management systems. Attackers can escalate privileges by creating administrat...

CVE-2025-26357

MEDIUM CVSS 4.9 Feb 12, 2025

This vulnerability allows authenticated remote attackers to read sensitive files on Q-Free MaxTime systems via path traversal attacks. Attackers can access files outside the intended directory by craf...

CVE-2025-26350

MEDIUM CVSS 4.9 Feb 12, 2025

This vulnerability allows authenticated remote attackers to upload malicious files to Q-Free MaxTime systems via template file uploads. Attackers can potentially execute arbitrary code or compromise t...

CVE-2025-26352

MEDIUM CVSS 6.5 Feb 12, 2025

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to delete sensitive files by manipulating HTTP requests. It affects all installations running version 2.11.0 o...

CVE-2025-26355

MEDIUM CVSS 6.5 Feb 12, 2025

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to delete sensitive files via crafted HTTP requests. It affects Q-Free MaxTime versions up to and including 2....

CVE-2025-26346

MEDIUM CVSS 5.5 Feb 12, 2025

This SQL injection vulnerability in Q-Free MaxTime allows authenticated attackers to execute arbitrary SQL commands via crafted HTTP requests to the editUserGroupMenu endpoint. It affects all versions...

CVE-2025-1102

MEDIUM CVSS 5.5 Feb 12, 2025

A CORS misconfiguration vulnerability in Q-Free MaxTime allows attackers to bypass origin validation and perform cross-origin attacks. This affects all unpatched Q-Free MaxTime systems up to version 2...