CVE-2025-1102
MEDIUMQ-free Maxtime < 2.11.0 - Origin Validation Error
Title source: ruleDescription
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URLs or HTTP requests.
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
1.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-346
Status
published
Affected Products (1)
q-free/maxtime
< 2.11.0
Timeline
Published
Feb 12, 2025
Tracked Since
Feb 18, 2026