CVE-2025-26349
Published: 12 February 2025
Description
Adversaries may modify host software binaries to establish persistent access to systems.
Security Summary
CVE-2025-26349 is a CWE-23 Relative Path Traversal vulnerability in the file upload mechanism of Q-Free MaxTime versions less than or equal to 2.11.0. Published on 2025-02-12T14:15:34.960, it carries a CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). The issue enables an authenticated remote attacker to overwrite arbitrary files through crafted HTTP requests.
An attacker requires high privileges (PR:H) to exploit this vulnerability over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). Successful exploitation allows overwriting arbitrary files, resulting in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H) within the unchanged scope (S:U).
Mitigation details are available in the advisory published by Nozomi Networks at https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-26349.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Path traversal in file upload enables arbitrary file overwrites, facilitating ingress tool transfer (T1105), exploitation of public-facing app (T1190), web shell deployment (T1505.003), and binary compromise (T1554).