CVE-2025-1102 Details
Description
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URLs or HTTP requests.
A vulnerability allowing origin validation errors in the CORS configuration has been identified in Q-Free MaxTime versions through 2.11.0. This flaw allows an unauthenticated remote attacker to manipulate the device's confidentiality, integrity, or availability by sending crafted URLs or HTTP requests.
No official solution has been communicated by the vendor. As a temporary measure, it is recommended to exercise caution when opening untrusted links or visiting external websites while using a browsing session connected to the management web application of devices running Q-Free MaxTime versions through 2.11.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-1102 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| q-free maxtime | <= 2.11.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Initial Analysis | [email protected] |
| Feb 12, 2025 | New CVE Received | [email protected] |